Most security tools are noise generators. Figure out how to separate the alerts that need attention from the rest.
Completely reflects my experience. Most dashboards have 99%+ noise that is useless from an operational perspective, and the inefficiency of Blueteam vs Redteam usually represents "how long until I can find the actual data points that matter" in the dashboards.
(That was the reason I went with the peer-to-peer and SBOM idea, trying to reduce as much noise as possible)