2013-11-19 09:55 AM
I know that SA is suppose to be fast but I seem to be doing a lot of waiting.
When I try to query for 45 minutes worth of log data in the investigation module for one device type it is taking forever to load.
The type I am trying to query is rhlinux and I only have 580k events in that one section of time, is there a reason it is taking so long to query? 20+min.
2013-11-19 07:25 PM
Hi Sean. There could be an issue with your index settings or the type of query you are trying to do. I would suggest getting in touch with the SA Tech Support crew who can review your settings and make recommendations to help you.
2013-11-19 07:25 PM
Hi Sean. There could be an issue with your index settings or the type of query you are trying to do. I would suggest getting in touch with the SA Tech Support crew who can review your settings and make recommendations to help you.