Hello
What options there are to tune search from already accelerated data model with 3+tb data?
the slowliness comes from using by clause.
search:
| tstats summariesonly=true count FROM datamodel=mydatamodel WHERE earliest=-7d@d BY field1, field2
So far I have checked usage for cpu, memory on sh and idx but nothing unusual. (No high usage for nothing.)
Datamodel status is 100% done