REDUCING SOC ANALYST ALERT FATIGUE THROUGH LLM-ASSISTED TRIAGE: A PROVIDER-AGNOSTIC SUMMARIZATION PIPELINE FOR WAZUH
##doi.readerDisplayName##:
https://doi.org/10.68023/m5wjsk50Kalit so‘zlar:
security operations centre, alert fatigue, large language model, Wazuh, triage automation, prompt injection, structured output, human-in-the-loopAbstrak
The volume of alerts processed by Security Operations Centres (SOCs) often exceeds analysts’ capacity for sustained attention. Even lowpriority notifications require analysts to examine raw logs, interpret rule metadata, and make an initial determination as to whether an alert constitutes a true positive or a false positive. This contributes to alert fatigue and increases the risk that significant security events may be overlooked. This article presents an open-source, provider-agnostic system that uses a large language model to perform the initial triage of alerts generated by Wazuh 4.9.2. The system combines a severityprioritized summarization service with a read-only conversational assistant operating within the analyst’s existing access permissions. Importantly, the LLM component is isolated from the primary alerting pipeline; therefore, a model or provider failure does not affect Wazuh’s ability to detect and record threats. Engineering verification demonstrated that the system successfully passed all quality-control tests. However, because the accuracy of its conclusions was not evaluated against a human-labelled ground-truth dataset, the results confirm the system’s technical and operational feasibility rather than its absolute reliability in making final security decisions.
References
1. Alahmadi, M., et al. (2025). Alert fatigue in security operations centres: Research challenges and opportunities. ACM Computing Surveys. https://doi.org/10.1145/3723158
2. Hassan, W. U., Guo, S., Li, D., Chen, Z., Jee, K., Li, Z., & Bates, A. (2019). NoDoze: Combatting threat alert fatigue with automated provenance triage. Proceedings of the Network and Distributed System Security Symposium. https://doi.org/10.14722/ndss.2019.23349
3. Habibzadeh, A., et al. (2025). Large language models for security operations centers: A comprehensive survey.
4. Hassanin, M., & Moustafa, N. (2024). A comprehensive overview of large language models for cyber defences: Opportunities and directions.
5. Wei, B., Tay, Y. S., Liu, H., Pan, J., Luo, K., Zhu, Z., & Jordan, C. (2025). CORTEX: Collaborative LLM agents for high-stakes alert triage.
6. Liu, Y., Tao, S., Meng, W., Yao, F., Zhao, X., & Yang, H. (2024). LogPrompt: Prompt engineering towards zero-shot and interpretable log analysis. Proceedings of the IEEE/ACM 46th International Conference on Software Engineering: Companion, 364–365.
7. Hahn, F., Mamoon, M., Bardas, A. G., Collins, M., Dudek, J. L., Lende, D., & Ou, X. (2026). Nondisruptive disruption: An empirical experience of introducing LLMs in the SOC. Workshop on Security Operations Center, co-located with NDSS. 8. OWASP Foundation. (2025). OWASP Top 10 for Large Language Model Applications. https://owasp.org/www-project-top-10-for-large-language-model-applications/
9. Wazuh, Inc. (2026). Wazuh: The open-source security platform. https://wazuh.com/