User is asking me when did we start logging their project “my-project” in cloud logs.
If I UDM search on project = “my-project” for the past year ,I get the “too many results” warning and the time graph won’t show up for the whole 1 year I’m searching.
“WARNING: Can't show all results because the query is too broad. Events are sampled. Try a more specific query.”
In Splunk I’d just use index = foo | fields index and I’d be done in a second.
Instead in SIEM I have to spend time researching looking for a field/value pair that doesn’t occur very often
There’s got to be an easier way to do this