Security Compliance

Improper Historical Search Queries can impact SEM performance

This article describes how initiating poorly thought searches can negatively impact SEM performance and includes instructions for adjusting the maximum search setting.

First published date

4/18/2019 7:38 PM

Last published date

6/6/2019 7:43 PM

Overview

The historical Search Dashboard and Live Filter Events dash boards both have maximum number of events that are shown to avoid negative Performance impact on SEM.

Initiating searches with a high maximum threshold can negatively impact Security Event Manager (SEM), formerly Log & Event Manager (LEM), performance.
On average, every 1000 returned search results consumes approximately 100MB of RAM, which can increase up to 10GB for one search query if the threshold is set to the 100,000 maximum. Predictably, executing multiple search queries simultaneously (Scheduled searches / multiple users running searches parallelly) will add additional strain to system resources and cause diminished performance.

Product section

Security Event Manager

Cause

  1. Searching for Long time range
  2. Nested Group Searches returning large results
  3. Nested Group Searches with Wild Card IP addresses

Resolution

Lowering your maximum search threshold in the SEM Events Console can improve performance for individual and simultaneous search queries. To lower your maximum search threshold:

  1. On the SEM Events Console toolbar, click the Settings (gear) button.
  2. On the Settings page, click the Search tab.
  3. Enter the maximum number of search results, and then click Save.

To return to the SEM Events Console, click Monitor.

Also, if you used user defined groups in historical searches that results large results or the search query is very large it will have same negative impact.

  • Avoid using Wild cards in User defined group where possible or minimize.
  • Keep the search query to manageable limit (10 K chars limit recommended)