From 1e84ee871bb00f373afca40efe47cd7fb0412495 Mon Sep 17 00:00:00 2001 From: Scott Brumley Date: Wed, 23 Sep 2026 20:48:08 -0400 Subject: [PATCH] fix(soc-framework-nist-ir-ai): repoint MTTI at a verdict anchor that exists Same defect and same fix as the base pack. MTTI returned null on every case. Two problems in one query: - the verdict anchor was event_type = "analysis_complete", which is never written to xsiam_socfw_ir_execution_raw. Same root cause as the MTTD fix in #1170. Now anchored on phase = Assessment, so it is producer-agnostic. - the start anchor counted only commands in phase Analysis, which is 14 rows across 5 cases. Investigation commands are emitted under Enrichment. The anchor now spans Analysis and Enrichment. Measured on a reference tenant: 0 cases before, 1,843 cases at 1.29 min after, against a 58s baseline. The max-based structure was already correct and is unchanged. --- .../XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json b/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json index 7c0ec99c..cbefa88d 100644 --- a/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json +++ b/Packs/soc-framework-nist-ir-ai/XSIAMDashboards/NIST_IR_AI_Value_Driver_Metrics.json @@ -989,9 +989,9 @@ "widget_key": "xql_1776910000012_ai", "title": "MTTI (min)", "creation_time": 1776900000001, - "description": "Mean Time to Investigate - framework first touch -> analysis_complete write per incident. Requires socfw-post-to-dataset task in Analysis Evaluation playbooks. Minutes.", + "description": "Last investigation command to assessment verdict, in minutes. Max-based: the final enrichment or analysis command, not the first. Producer-agnostic verdict anchor.", "data": { - "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| alter t_ms = to_epoch(_time, \"millis\")\n| alter t_first = if(event_type = \"command\" and uppercase(phase) = \"ANALYSIS\", t_ms, null)\n| alter t_verdict = if(event_type = \"analysis_complete\", t_ms, null)\n| comp max(t_first) as first_ms, max(t_verdict) as verdict_ms by incident_id\n| filter verdict_ms != null and first_ms != null\n| alter mtti_ms = subtract(verdict_ms, first_ms)\n| filter mtti_ms > 0\n| alter mtti_minutes = divide(mtti_ms, 60000)\n| comp avg(mtti_minutes) as avg_mtti_min\n| view graph type = single subtype = standard yaxis = avg_mtti_min", + "phrase": "dataset = xsiam_socfw_ir_execution_raw\n| alter t_ms = to_epoch(_time, \"millis\")\n| alter t_first = if(event_type = \"command\" and uppercase(phase) in (\"ANALYSIS\",\"ENRICHMENT\"), t_ms, null)\n| alter t_verdict = if(uppercase(phase) = \"ASSESSMENT\", t_ms, null)\n| comp max(t_first) as first_ms, max(t_verdict) as verdict_ms by incident_id\n| filter verdict_ms != null and first_ms != null\n| alter mtti_ms = subtract(verdict_ms, first_ms)\n| filter mtti_ms > 0\n| alter mtti_minutes = divide(mtti_ms, 60000)\n| comp avg(mtti_minutes) as avg_mtti_min\n| view graph type = single subtype = standard header = \"MTTI (min)\" yaxis = avg_mtti_min", "time_frame": { "relativeTime": 2592000000 },