Trying to find out what is most efficient in this scenario resource/time wise.
We want to do a search across the last 90 days that looks for sshd and matching a user, to look for logins.
Is it better to loop over a user list inputting a search for each user separately as 'earliest=-90d sshd user=$var_user' one at a time or to do one search with all the users OR'ed like so 'earliest=-90d sshd (user=$var_user OR user=$var_user1 OR....)'?
This is in the context of the user list being hundreds of users long. So are hundreds of stacked up long-length single-term searches better than lots and lots of ORs across the same time range in a single search.
Thoughts?
Scott
The single search is most probably the most efficient one.