I've written a log search that essentially let's me see how many distinct files have been downloaded from Google Drive and gets counted by user. I'm wanting to create an outlier now so I can have it alert when the number of downloads spikes out of the ordinary (potentially implying that one of our users is dumping a bunch of files to take outside of the organization). However, I'm having a hard time getting this component in.
In order to create and use an outlier, there is a requirement that timeslice is needed. When I try to incorporate timeslice into my log search and run it, it simply throws up the error that timeslice cannot be found even though SumoLogic looks to recognize it. Anyone else run into something similar or have already gone through setting this up for Google Drive?
Please sign in to leave a comment.