I want to convert this query to tstats for faster searching
can you help me convert it
index=win-security host=srv001 user IN ("*adminuser")
[ search index=paloalto sourcetype=pan:threat]
You can only use tstats on indexed fields, so unless the 'user' field is indexed, you cannot use tstats in the first parts of the search.
It's not entirely clear what you're trying to do with your subsearch. What are you trying to do there?