An untested detection is a hypothesis
A rule that has never fired might be perfectly tuned or silently broken. From the console those look identical, and only a deliberate test separates them.
A rule that has never fired is in one of two states, and you cannot tell which from the console.
Either it works and the thing it looks for has not happened, or it broke at some point and nobody noticed. Both states present identically: enabled, healthy, zero alerts. The dashboard is not withholding the answer, it genuinely does not have it.
Two cheap ways to find out. Search your historical data for what the rule describes, and if you find the pattern on a day the rule stayed quiet, you have your answer immediately. Or produce the benign version of the behaviour yourself, somewhere controlled, and watch what happens.
The second one has to run end to end. A rule matching is not the same as somebody seeing an alert, because the pipeline, the routing and whatever suppression somebody added last spring all sit in between. Test the whole path, from the event being generated to the alert arriving where a human would look.
None of this is exciting and it is the difference between a control and an intention.
Pull up your rules and sort by the date each last fired. The ones with no date at all are not your quiet successes. They are your unanswered questions.
CHECK YOURSELF
A rule has been enabled for a year and has never produced a single alert. What does that tell you?
SHOW THE ANSWER
Nothing yet, because a working rule and a broken one look the same
Why. Zero alerts is equally consistent with a rule that works against something that never happened, and a rule that has been quietly broken since the day it shipped. The console cannot tell those apart, which is why silence needs a deliberate test rather than an interpretation. Disabling it throws away the question along with the rule.