I have this problem too.
In all of searches that i did, rate is too slow and i can't see a complete result. for example i search this query:
"index="fw251_1" | selfjoin session_id | eval dest = if(direction="inbound",src_ip,dest_ip) | stats count as "Connection Allowed" by dest | sort -"Connection Allowed" | rename dest as "Destination IP Address" | head 10" during "last 60 mins"
it took about 8 hours to complete and i saw 60 millions logs.
If i want to see results for above search during one day, i will wait for 1 week!!!!
Why should i do for this problem?
My resources like Cpu, Ram, ... are enough in my splunk server.
... View more