Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM Reports

$
0
0

LEM keeps the last seven days worth of data uncompressed to make Reporting and searching faster.  The assumption is that you'll more frequently want to be investigating what just happened, not ancient history.

 

After 7 days, LEM compresses the data.  That means any search that includes dates/times outside the last 7 days will require more time and resources as LEM has to find the right compressed DB partition, decompress it, search it, get the data, return the data, re-compress it and move to the next section.

 

There are also limits in Reports, so any query that would return more than 10 million results (I think) will fail.

 

If you're regularly expected to present "weeks" worth of data, it may be more efficient to schedule weekly reports and then show multiple weekly reports instead of one "many weeks" report.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>