Only way to reduce alert fatigue
What do you like best?
The best thing about the Respond Analyst is that it takes a huge volume of events and alerts and with the ability to provide context, take those to just a handful of relevant alerts a week. Addresses a real problem of alert fatigue.
What do you dislike?
There is not much reporting or metrics available at this point in time. It's still relatively new and in development. I know it's coming but it's weak at the moment.
Recommendations to others considering the product:
If you need a tool to reduce alert fatigue, this is the place to start. I can't tell you how much better I feel knowing that we're responding to incidents that matter in the context we provide.
What problems are you solving with the product? What benefits have you realized?
The biggest problem we are targeting is alert fatigue. We send 10's of thousands of alerts from Palo threat and Suricata and get about 5 legit alerts a week. That's a huge benefit for our analysts as they aren't wasting time on triaging incidents that don't matter.