Try running this query:
(component=Hostwide host=splunkitsi index=_introspection sourcetype=splunk_resource_usage)
| eval cpu = 100 - 'data.cpu_idle_pct'
| timechart Median(cpu) AS "cpu" by host
There are plenty of good searches in the monitoring console you can use to try figure out why performance is bad.
All the best.
Just simple search index=_introspection does not bring back any result for me. Would that mean I have no authorization for it? Or is it coming first with the ITSI product, which we do not have?
No its not ITSI. You will need to be a Splunk admin role to see it.