Recommended Fields for Metric Collection

October 2, 2025 ยท View on GitHub

Metrics require fields, queries, and manual work. This section also suggests which ticketing system and form fields are recommended to allow proper recording/reporting of metrics.

Recommended Fields for Metric Collection

  • DateTime Occurred
  • DateTime Detected
  • DateTime Contained
  • DateTime Expelled
  • DateTime Owner Notified
  • DateTime Escalated
  • Recommended Mitigation
  • Severity
  • Source Playbook
  • Source Signature
  • Origination
  • MITRE ATT&CK Technique

Recommended Metrics

  • Average Cost Per Incident
  • Average Time to Detect
  • Average Time to Escalate
  • Average Time to Contain
  • Average Time to Expel
  • Average Time to Notify
  • Incidents Opened in a given time frame
  • Incidents Closed in a given time frame
  • Count of Incidents per Recommended Mitigation
  • Count of Incidents per Severity
  • Count of Incidents per Severity Not Reviewed Within Required Time
  • Count of Incidents per Alert/Rule/Signature
  • Count of Incidents per Playbook
  • Count of False Positive Incidents Per Playbook
  • Count of Incidents per Attack Technique

See Also