TL;DR
Our SOC's RAG pipeline retrieves over 142,000 closed XSOAR security tickets to ground
investigation answers. After exhausting the easy wins — chunking, top-k, reranker
choice — we still saw the right historical ticket land at rank 5-10 too often, and
the LLM grounding its answer in a near-miss neighbor.






