After installing the CrowdStrike app for Splunk, version 1.0.4, any saved/scheduled/correlation search using tstats are running extremely slow.
The CrowdStrike Falcon App for Splunk version 1.0.4 ships with a macro called summariesonly
which translates to "summariesonly=false". Because of how configurations are merged, Splunk was using the macro from this app instead of the pre-configured macro that ships with ES. Disabling CrowdStrike's macro fixed this for me.
The CrowdStrike Falcon App for Splunk version 1.0.4 ships with a macro called summariesonly
which translates to "summariesonly=false". Because of how configurations are merged, Splunk was using the macro from this app instead of the pre-configured macro that ships with ES. Disabling CrowdStrike's macro fixed this for me.