Which would be a more efficient search for your car keys?
"somewhere in Texas"
OR
"somewhere in Dallas"
OR
"somewhere in my house"
The more details that you give, the fewer places (buckets of compressed data) need to be searched. If you know that
index="Dallas" AND sourcetype="my house", then say so!
That being said, as long as you are fully qualifying indexed fields (e.g. host="MyHost"), it is MUCH less of a big deal. Also, if this is ad-hoc stuff, it is not too bad. It can really add up, though, if you save and schedule open-ended searches like this. A running search fully consumes a core on each indexer and the search head.
... View more