I think it is impossible to compare two different types of data storage by using the same queries. SQL and Splunk can both use the phrase "where x > 50", but they work in very different ways.
To get a real comparison, I would prepare a list of requirements that are relevant to your needs, but generic: "we need to identify all users who have exceeded their bandwidth terms of service." Then formulate the searches/queries in each tool.
My personal is experience is that Splunk is blazingly fast for some queries that were impossible for an RDBMS. But it can be slower for searches where you have a priori knowledge of the data and the structure - and both the data structure and the query structure are unchanging.
If you ask questions about specific queries (and provide some sample sanitized data), I am sure that the folks on this forum can give you some great optimization tips. For example, if you turn off "Field Discovery", your searches will probably run significantly faster. I often see a 3x improvement, but it is highly dependent on the data. It's certainly easy to try...
... View more