Skip to content

Parser for CISCO ISE in Sentinel consuming too much resources #13791

@tsanjev

Description

@tsanjev

When Running the CiscoISEEvent
https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Cisco%20ISE/Parsers/CiscoISEEvent.yaml

Returns the following
Your query is consuming too much resources due to heavy use of 'sort' operator.

  • Use the portal to sort the results or try to use 'sort' as the final operator of the query.
  • Apply early filtering to reduce the number of values.
  • Consider using sampling.

Time Range = sentinel defaults ; 24h & max 1k results

Metadata

Metadata

Labels

ParserParser specialty review needed

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions