The architect designs the metrics framework that measures SOC effectiveness. Key metrics include MTTD (Mean Time to Detect), MTTR (Mean Time to Respond/Resolve), false positive rate, and escalation rate. These metrics feed executive dashboards and drive continuous improvement.
In Splunk ES, these metrics can be extracted from Notable Event audit data. The architect builds scheduled reports that calculate rolling 30-day averages, enabling the SOC manager to track trends and demonstrate value. Alert fatigue (measured as false positive %) is a critical indicator of detection quality.