I performed this search:
| datamodel Authentication Autherntication search | search Authentication.src=xxx.yyy.com (over past 60 min)
the results took 6.26 min
the search against raw:
index=* xxx.yyy.com
and the same number of results only took 10 seconds to return...
I've experienced the same kind of behaviour.
in my opinion :
in the second case, splunk uses bloom filter -> matches only some buckets depending on your search -> can be very fast
in your dm case, splunk has to build the dm then filter
the build the dm will be for a lot of data -> rather slow. the filtering after is very fast.
but if you accelerate the dm, it could be faster than normal search