Every other product I have worked with properly indexes fields and allows for quick searching. Please work on this area. Searches are basically not worth it in the SIEM. We try to avoid it when we can (kind of defeats the purpose of the SIEM to begin with).
Please consider altering the interface to something more like Splunk, ELSA, ElasticSearch to allow for dymanic query building, selecting of input data, and free form input.