Hi it’s hard to help you without more information about your environment and queries. You could try to look if this helps https://conf.splunk.com/files/2020/slides/TRU1761C.pdf There are many more presentations which could help too? r. Ismo
... View more