Allow Exporting Search Data to CSV
planned
Chris Bisnett
planned
Chris Bisnett
Would something like the first 10,000 rows returned by the query be reasonable? Some queries could return gigabytes or terabytes of data and that wouldn't be ideal for reviewing in a CSV.
We will have a separate capability to export all data for a specified time range for things like taking your data somewhere else or when an incident happens and you need to provide data to the incident response team.
J
Jonathan Pilkington
Chris Bisnett I feel like that would be reasonable. Main thing is if there is an ongoing investigation of a incident I would need some way to share the data I am looking at.
J
Jonathan Pilkington
Forgot to mention reason for this is if say insurance got involved after a incident they might want log data from specific time periods. So basically a way to share data outside the org.