Search capability, including concurrency has nothing to do with indexed volume. It is mostly constrained by CPU cores on the search head, plus settings, intersecting with actual demand. Read more here:
Thanks much for you response.
I understood from the docs that concurrent searches are related to CPU cores but If it's a Splunk enterprise version we have control over infrastructure. when it's Splunk cloud where do not know about the CPU cores/infra, how many concurrent searches are allowed with better performance?
Math is not the right approach here. Instead monitor for logs that clearly indicate either
skipped searches. If you have these, you have some kind of concurrency problem.