Hey everyone, I’m hoping to get some real-world feedback from other Exabeam users. Our revops team uses timeline generation heavily for security incident reviews tied to sales and finance system access. Lately, we’ve noticed that for a subset of our users—specifically those with very high event volumes from our CRM and ERP systems—the timeline generation is taking upwards of 3-4 hours to complete. For most users, it’s under 30 minutes.
We’ve checked the obvious: user entity activity counts, indexing status, and our ingestion rates. Everything seems normal on our end, and there’s no clear pattern linking it to a specific data source or role—just the volume of events per user.
Is this a known scaling issue? I’m trying to figure out:
* Is this just the expected behavior when a user entity has, say, 2M+ associated events?
* Are there specific configuration tweaks in the Advanced Analytics settings that actually help, or is it purely a hardware/resource problem?
* How are others forecasting and planning for this? It’s starting to impact our SLA for internal security reviews.
From a pure numbers perspective, our average events per user is around 500k, and those timelines are fast. The problem is with our “power users” in the revenue and sales ops domains. Any shared experiences or data points would be really helpful.
- Lisa
Show me the pipeline.