I am running a BIG TSTAT search off a Datamodel - The bottle neck is dispatch.stream.local + dispatch.fetch (I have been told this is IO). However when i look at the IO[15%], CPU[30%] and disk[10%] Access its all low, so what can i change to make it faster?
I cant really change the search.
I have one machine running one indexer and one search head.
IF the answer is to add more indexers, then how does that work, will the Datamodel not be over 2 Indexers if so what configuration do i need to the indexers, Cluster , replication etc..
Cheers in advance
Screen reader users, click here to skip the navigation bar
Search job inspector
This search is still running and is approximately 100% complete.