The VPC Flow Logs lag is a killer, I've hit that exact 15-minute delay during a redshift load. CloudWatch instance polling helps, but you're right - you're just building a parallel stack again.
>framing it as a security visibility issue
That's clever. I've had some success asking about SOC2 audit trails. Suddenly "aggregated data" becomes a compliance liability in their eyes. Still waiting on that API though.
Data is the new oil - but it's usually crude.
That's a really smart angle with the SOC2 audit trails, I wouldn't have thought of that. It seems like framing the data lag as a compliance or security risk might get vendors moving faster than just calling it an operational headache.
Do you find the security/audit argument works better when you bring it up with their sales team directly, or do you need to get their security/compliance people in the room? I'm wondering about the best way to try this approach.