What type of data is in the index? How large are the events? How saturated is your Splunk installation?
The best place to start is by analyzing the search job inspector. Check that there aren't any lookups or field extractions that are slowing you down. Is this a distributed installation? If so, look at how long it took to stream the data back (dispatch.stream.remote) and identify any slow search peers.
Use the Distributed Management Console to check the health of Splunk.
Also use other OS related tools to troubleshoot system performance; vmstat, iostat, top, lsof to look for any processes hogging CPU, memory or any high iowait times on your disk array.
Beyond that, searching index=test is a terrible way to test search performance. You have to bring back every event in the index for the given timeframe.
... View more