There are a few things you can do to optimize your searches. In particular, you can take advantage of the following:
1. Field Extraction Rules to parse your logs at ingestion time
2. Partitions to "bucket your data" and improve search performance
3. Scheduled Views to pre-aggregate data that gets searched and aggregated on a regular basis.
You can learn about each of these on this Optimization webinar: https://www.sumologic.com/analyst-training/#manage
Additionally, we are running Office Hours tomorrow, March 1st, where we can help you with your use case. To register for this, please go to: https://www.sumologic.com/training/#public
Please sign in to leave a comment.