As the title said, if we have a field: "sourcetype=log4j" for all result, Should I add it to the search or remove it from our search to reduce the search time?
Adding the sourcetype to your base search should reduce the search time.
Adding the sourcetype to your base search should reduce the search time.