Noticing a big difference in time it takes to do a search on 2 different fields in a log. Is this just due to the slower one being at the end of the log? Its a firewall log (CIM)
Please tell us more about the two fields. Share the two queries, if you can.
just noticed a big difference it took to search for an dst ip verses a source ip. Basic query
index=firewall dst="xxx.xxx.xxx.xxx"
vs
index=firewall src="xxx.xxx.xxx.xxx"
It takes a lot longer for the search to complete for the src . I noticed that src was at the end of the log. I was wondering if that is the reason