I am particularly interested in the fields data.elapsed and data.mem_used under introspection. Can we calculate runtime and memory usage from these values?
You can use following links to know more about what is getting logged in index=_introspection.
http://docs.splunk.com/Documentation/Splunk/7.1.1/Troubleshooting/Whatdatagetslogged
http://docs.splunk.com/Documentation/Splunk/7.1.1/RESTREF/RESTintrospect#server.2Fstatus.2Fresource-...
Based on description on 2nd link, data.elapsed is the run time and mem.used is memory (physical) usage.
Thank you. Can we check with the search_id from _introspection under _audit to find the corresponding events?