We found that unless you configure default to be your domain searches took forever, once we set default to our domain.
Splunk are Linux guys and sometime forget that us windows guys assume domain name means domain name, not in this case.
Where it says domain name=default, that's just a label. Leave domain name = default, your domain name goes in alternative domain name.
Previously even with some other label configured and tested to point to our domain, the search would takes 15-20 minutes. Once changed, much less than 1 minute for large searches.
... View more