Skip to main content

Hey Everyone,

Over the last 2-3 months (it might have been longer), I've noticed that the SIEM UI has been incredibly slow, and searches are taking much longer than in the past. Now, my searches were never optimized to begin with (I am a big fan of regex searches...), but my search style has been the same from the start, and it feels like the search engine and UI have gotten 10 times worse. Going from the base page to the search page (OrgHere.backstory.chronicle.security to OrgHere.backstory.chronicle.security/search) can sometimes take a minute, and god help me if I want to load a search! It's like a slideshow at that point! Using the user interface can be like this too, just all over the place (alerts and IOC page, dashboards, etc., etc.).

I've tested on multiple systems, and all my colleagues have the same issue. At this point, I'm not sure what's going on and would love some ideas!

Thanks!

Haven't had that experience thankfully, except intermittently with things like feeds loading longer then usual every now and then. We work in a lot of instances. I wonder if there's something specific about your instance that has slowed down. There could be browser type things that slow down response times since Chronicle is very front-end heavy, for example I noticed that when I'm presenting it's EXTRA slow, but the minute i stop presenting it goes back to normal. Since you mention multiple people have that issue, could be something else entirely and may require some back and forth with support. 

The only issue I had was with hostname = "specific name in quotes". There was one specific instance that was running into issues with that but we had a hard time replicating on other instance. It doesn't seem like the issue on your end, i'm curious what does your browser say (what api endpoints load the slowest). Keep us posted in your investigation!


Reply