“…Third, having more data sources increases the overall number of events and, in many cases, the number of false-positive alerts. It is often mentioned that there is too much (useless) data in general [22], and too many (false positive) alerts [9], [25], [32], [159], [164]. Analysts are overloaded with a high volume of such alerts and face a typical "needle in a haystack" problem when trying to filter the noise [12], [159].…”