diff --git a/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json b/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json index 7c0ec99c..cbefa88d 100644 --- a/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json +++ b/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json @@ -989,9 +989,9 @@ "widget_key": "xql_1776910000012_ai", "title": "MTTI (min)", "creation_time": 1776900000001, - "description": "Mean Time to Investigate - framework first touch -> analysis_complete write per incident. Requires socfw-post-to-dataset task in Analysis Evaluation playbooks. Minutes.", + "description": "Last investigation command to assessment verdict, in minutes. Max-based: the final enrichment or analysis command, not the first. Producer-agnostic verdict anchor.", "data": { - "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| alter t_ms = to_epoch(_time, \"millis\")\n| alter t_first = if(event_type = \"command\" and uppercase(phase) = \"ANALYSIS\", t_ms, null)\n| alter t_verdict = if(event_type = \"analysis_complete\", t_ms, null)\n| comp max(t_first) as first_ms, max(t_verdict) as verdict_ms by incident_id\n| filter verdict_ms != null and first_ms != null\n| alter mtti_ms = subtract(verdict_ms, first_ms)\n| filter mtti_ms > 0\n| alter mtti_minutes = divide(mtti_ms, 60000)\n| comp avg(mtti_minutes) as avg_mtti_min\n| view graph type = single subtype = standard yaxis = avg_mtti_min", + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| alter t_ms = to_epoch(_time, \"millis\")\n| alter t_first = if(event_type = \"command\" and uppercase(phase) in (\"ANALYSIS\",\"ENRICHMENT\"), t_ms, null)\n| alter t_verdict = if(uppercase(phase) = \"ASSESSMENT\", t_ms, null)\n| comp max(t_first) as first_ms, max(t_verdict) as verdict_ms by incident_id\n| filter verdict_ms != null and first_ms != null\n| alter mtti_ms = subtract(verdict_ms, first_ms)\n| filter mtti_ms > 0\n| alter mtti_minutes = divide(mtti_ms, 60000)\n| comp avg(mtti_minutes) as avg_mtti_min\n| view graph type = single subtype = standard header = \"MTTI (min)\" yaxis = avg_mtti_min", "time_frame": { "relativeTime": 2592000000 },