We study the current limitations of systems processing alarms generated by network intrusion detection systems (NIDS ) and propose a new automatic approach that improves the filtering mechanism . Our main contributions are as follows: 1 . We have proposed an architecture of alarm filtering analyzing logs and NIDS alerts and trying to filter out false positives . 2 . We study the dynamic aspect of the proposed architecture . Processing real-time architecture poses several challenges in adapting this architecture in relation to changes that may occur over time . We have identified three problems to solve : (1) adapting the architecture towards the evolution of the monitored network, integration of new machinery, new routers , etc. , (2) adaptation of the architecture with respect to the emergence of new types of attacks and (3) adaptation of the architecture. with the appearance or sliding type behavior. To solve these problems , we use the concept of distance rejection proposed in pattern recognition and statistical hypothesis testing. All our proposals are implemented and led to experiments we describe throughout the document. These experiments use alarms generated by SNORT , an intrusion detection system based network - monitoring network of the Rectory of Rouen and is deployed in an operational environment . This is important for the validation of our architecture because it uses alarms from a real environment rather than a simulated environment or laboratory that may have significant limitations.