Hi Splunk experts,
I am running below query and the results get loaded much faster for admin users compared to regular users.
| tstats count from datamodel=Web where earliest=-7d latest=-15m index=************* by _time span=15m | sort -_time
Searches ran by admin gets completed in less than a minute and user searches runs for many hours. Please can someone help?
Regards,
Dinesh