Hello @lusynda. The Elastic SIEM is doing a bit more work than just one KQL search. When you are in the Elastic SIEM, the KQL search is filtering multiple queries on the page for each data widget or table that you see. The KQL search is only part of the query. Each widget will have an inspect button in the top right corner. The timeline inspect button is in the top right actions dropdown. This will bring up a modal, telling you the index patterns queried, and the request tab shows the full query that can be run in the console. This includes the KQL query.
We have a new "Data Sources" feature in
7.10 that gives the user control over the index patterns queried. You may be seeing faster performance in the console because you are only querying across one index pattern. By narrowing which index patterns are queried, you will see a performance boost.
Here is what this feature looks like on the Hosts page:
And here it is in Timeline:
Please let me know if any of this helps.