When I use this command ( table ) it runs at a slow speed .... please help me.
Thank you for your answer.
Oh, this one killed me for a while.
fields
is a streaming, distributable command.
table
is neither. table
, as well as dropping all non-mentioned fields, reformats the data internally, and limits the results as per some system parameters. It may do other stuff, but the bottom line is that table
cannot run until all the results are returned to the search head, whereas fields
can be run at each indexer.
So, use fields
if you are up in the area where you are dealing with streaming distributable commands, and only use table
later, after everything is already on the search head.
Please share your full query. The table
command by itself usually is not a performance drag.