Does anyone know why I would be getting very bad browsing performance when searching through large events regardless if its on verbose or fast mode. It started happening after the latest Chrome upgrade but it is also happening on Safari and Firefox. We also updated to Splunk 7. No issues with any of the dashboards or searches with stats or visualization on Fast mode.
Thanks in advanced.
All of the data in those raw events is literally stored in the html that the browser has to load.
If this happens with smart mode or fast mode, then your search allows the raw data to be loaded into the Events tab or into a field in the Statistics tab (perhaps an _raw field).