Hi,
I'm very new to Splunk and I'm looking at a single node instance that's being used in our office to store a large amount of data (over 1 billion records) the performance is off with most searches taking minutes to complete. I was looking at the job inspector to see where the delays were lying and I was expected to see a lot of IO delay (which I do) However, there is this one field command.search.expand_search which takes about 50% of the total search time to complete, googling it brings up nothing. Can anyone shed any light on what is actually happening underneath?
Thanks
Splunk version is 7.0.0