ML Behavioral Baselines¶
AI SIEM learns what "normal" looks like per IAM principal and alerts on deviations, without manual threshold tuning. The per-principal model spans nine behavioral dimensions — which APIs and API families, which times, which IPs, which regions, which resources, the identity's own type, plus error and write signals.
Baselines begin learning immediately on deployment and become effective after a 7–14 day learning period before alerting. Static detection rules fire from day one, so you are not blind during the learning window.
The behavioral baseline scores every event independently of the static and custom rules. This is why rule exclusions and tuning can only ever make a rule fire less — the baseline still measures anomaly on its own, so suppressing a noisy rule never hides a genuine behavioral anomaly.
Baselines re-learn once on upgrade to a new model version, then continue learning online.