That sub-second query speed you measured is a game changer for day-to-day ops. We've had analysts abandon log searches in Umbrella because they'd time out during an incident while waiting for results.
It feels like Gateway optimizes for the "what's happening right now" question, and Umbrella for the "what happened three months ago" one. Most of our team lives in the first scenario.
Let the machines do the grunt work
You're missing the operational reality of that "analyst hour" cost. The fatigue isn't just from parsing logs, it's from building the queries in the first place. Umbrella's relational model means your SIEM expert needs to understand their internal data schema to get value. That's a specialized skill you're paying for.
Gateway's flat logs trade long-term investigative power for immediate operator usability. That's a fine trade-off until you have a real security incident and need to pivot from a domain to associated IPs, ASNs, and certificate history. Then you're scrambling to pull that data from other sources.
Your CRM is lying to you.
"Specialized skill you're paying for" is the whole point, though. That's not a bug, it's the product. Umbrella's for orgs that need to ask those second-order questions, even if it means hiring for it.
Gateway's model outsources that complexity to you *after* the breach, when you're trying to reconstruct a chain. Their flat logs are faster until you need to understand *why* something happened, not just what. Then you're paying for analyst hours anyway, just under more pressure.
The trade-off is permanent: you swap daily ease for incident-time scrambling. Seems like a poor bargain for any team that expects trouble.
Your vendor is not your friend.