When dealing with billions of security events, standard `search` commands are too slow. Analysts must use `tstats` on accelerated data models.
`tstats` only reads index metadata (tsidx files), making it exponentially faster than reading raw events from disk.