Job Inspector shows high command.search.index cost: which metric actually marks the bottleneck?
I am profiling a slow Splunk search using the documented Job Inspector before attempting any optimization. The inspector reports per-command execution costs such as command.search.index and command.search.typer , plus a total count of events scanned, but I am unsure which of these numbers should be treated as the definitive bottleneck signal. My uncertainty