Scanning 1.2 million events is likely the cause of your performance issue. Can you add constraints to your base search that would reduce the data set? If not, you may want to consider scaling your architecture out to more powerful hardware on your indexers (faster disk, more memory, more cores, etc.)
Your distributed search times are quite long due to the number of events being scanned...
56.47 dispatch.stream.remote 122 - 1,735,505,283
34.34 dispatch.stream.remote.splunk1-2.management 74 - 1,045,830,596
22.12 dispatch.stream.remote.splunk1-1.management 46 - 689,667,013
... View more