Hello,
I have upgraded Splunk Enterprise to 7.0.1. One of the search query is taking ages to finish it. Same query finished quickly in Splunk 6.x.
Splunk 6.6.1 = 5 secs
Splunk 7.0.1 = 26 mins (still running)
Does anyone have encounter such situation or have idea for this behaviour in Splunk 7.