TL;DR

Our SOC's RAG pipeline retrieves over 142,000 closed XSOAR security tickets to ground

investigation answers. After exhausting the easy wins — chunking, top-k, reranker

choice — we still saw the right historical ticket land at rank 5-10 too often, and

the LLM grounding its answer in a near-miss neighbor.