Using Splunk Enterprise 9.4.3 on Windows 2019. Our single search head is having some performance issues. Whilst searches in the UI are generally responsive and performant, try to configure anything in the UI (a search macro for example) can take up to 1 minute to display the dialog. This is common across nearly all configuration elements in the UI.
Basic analysis I have done on my end show a high rate of file acivity by Splunk processes particualy in the users/apps folders
Procmon trace for 90 seconds
Showing a large amount of file activity(Note: Windows Defender EDR/AV will scan most of this). Drilling down into the file activity