# Calculate response time for alerts

**URL:** <https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141>\
**Category:** Elastic Security\
**Created:** [June 27, 2024, 8:41am UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141 "2024-06-27T08:41:00Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![abubacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abubacker/32/122141_2.png) [@abubacker](https://discuss.elastic.co/u/abubacker)\
**Post date:** [June 27, 2024, 8:41am UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/1 "2024-06-27T08:41:00Z")

</div>

Dear All

I need to calculate response time from security alerts open to ack to closed

currently, from Kibana alerts logs, I'm able to get alert start time but when we ack or close time is not logged in alerts only workflow status is charged in the log

kindly let me know how to achieve this  
If anyone done this before

And if anyone has a SOC metrics dashboard to calculate MTTD, MTTR etc please share

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [June 27, 2024, 1:10pm UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/2 "2024-06-27T13:10:38Z")

</div>

Hi!

What version are you on? We added this capability (logging the workflow time change) in 8.12.

Thanks,  
James

---

<div class="post-metadata">

**Author:** ![abubacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abubacker/32/122141_2.png) [@abubacker](https://discuss.elastic.co/u/abubacker)\
**Post date:** [June 28, 2024, 6:27am UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/3 "2024-06-28T06:27:47Z")

</div>

We are using 8.11.4 and will upgrade to the new version  
Thanks for the information

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 28, 2024, 12:27pm UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/4 "2024-06-28T12:27:51Z")

</div>

Where exaxtly, what field / index can we find this data? Is the duration also logged somewhere?

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [June 28, 2024, 2:39pm UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/5 "2024-06-28T14:39:08Z")

</div>

@willemdh , it gets added to the alert document.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/2/42f7a6e2e2130fd51a41c1caeb6a27e9ac2d9ac3.png)

Re duration, we don't calculate it automatically, but it should be fairly easy to do with an ES|QL query now, if you would like to have this on a report or dashboard.

The assistant can also help here if you have access. Example:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e32a886b1305bd1f5557c2d311219548f2cd105.jpeg)

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 29, 2024, 9:24am UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/6 "2024-06-29T09:24:52Z")

</div>

Thanks @jamesspi =\> That seems indeed an amazing use case for the AI assistant. I did find the workflow\_status\_updated\_at field. The AI assistant can't help me though, but I guess what you are doing is a 8.14 feature.

Answer I got in 8.13.4:

`As a SOC analyst, I'm unable to generate this requested data through a text-based conversation as it requires accessing your SIEM tool Elastic. However, I can guide you on how to do this.`

Just a thought, we have up to 400 alerts / day. It seems like we will need a big context model if we would want to send all alerts as context?

Imho I think it would be useful if the mttd and mttr would be indexed somehow. Reporting on this get's complicated fast. Ideally we would like the daily average and max mttd and mttr grouped by severity.

---

<div class="post-metadata">

**Author:** ![willemdh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/willemdh/32/16922_2.png) [@willemdh](https://discuss.elastic.co/u/willemdh)\
**Post date:** [June 29, 2024, 9:34am UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/7 "2024-06-29T09:34:48Z")

</div>

@jamesspi Also fyi, when I ask for the ESQL query to do that

`Can you give me the ESQL query to do that`

it tells me:

`I'm afraid it's a bit difficult to generate a precise EQL (Event Query Language) query for your request without having specific schema details of your data model. However, I can provide a general guidance on how you could construct such a query using EQL.`

The general guidance given doesn't really help. I've tried asking the AI assistant for help generating ESQL queries before but never got a correct answer. In my experience, it tends to confuse syntax with other non-Elastic query languages.

For example when I say:

`I said Elastic "ES|QL", not EQL`

The answer given:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b134861185534b7bb8f556fdf08a8fe323e53846.png)

Any tips to make the AI Assistant give less confusing answers?

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [July 1, 2024, 1:20pm UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/8 "2024-07-01T13:20:50Z")

</div>

@willemdh, is your knowledgebase enabled?

> **[AI Assistant | Elastic Security Solution \[8.14\] | Elastic](https://www.elastic.co/guide/en/security/current/security-assistant.html#rag-for-esql)**

Also, we did indeed make significant improvements in 8.14 around query generation.

---

<div class="post-metadata">

**Author:** ![jamesspi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesspi/32/24479_2.png) [@jamesspi](https://discuss.elastic.co/u/jamesspi)\
**Post date:** [July 1, 2024, 1:21pm UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/9 "2024-07-01T13:21:43Z")

</div>

Re context windows - we also published this model matrix here:

> **[Large language model performance matrix | Elastic Security Solution \[8.14\] |...](https://www.elastic.co/guide/en/security/current/llm-performance-matrix.html)**

---

<div class="post-metadata">

**Author:** ![tareveor23](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@tareveor23](https://discuss.elastic.co/u/tareveor23)\
**Post date:** [July 23, 2024, 8:44am UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/10 "2024-07-23T08:44:36Z")

</div>

In which field or index is this data stored facing issue in a [calculator](https://mauricettecalculette.fr/)? Is there also a log for duration?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2024, 8:44am UTC](https://discuss.elastic.co/t/calculate-response-time-for-alerts/362141/11 "2024-08-20T08:44:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
