When a user keeps a dashboard/view which has auto refresh open, the internal logs(_internal) will have search * as an entry in sourcetype=searches against that user each time the dashboard get refreshed(Query that is being used in dashboard is not just *)
Is there a way to avoid this or to differentiate the actual search query when the user just types * in search bar(flash timeline)?
Here is my xml
OK. Just remove this param from your Switcher module:
<param name="requiresDispatch">True</param>
Just delete it entirely. That param is forcing a dispatch right where the Switcher is, and since there's neither a search nor a savedsearch defined upstream from that point, the framework is dispatching a "*" search over all time. Remove that one param and this dispatched search will go away. Also the removal thereof will not have any other effect on anything that I can see.
You're already using Sideview Utils 2.X (looking at your module config), and I think after this experience, you'll get a greater understanding by re-reading the "Introduction to Advanced XML" page, aka "framework_intro". It casts light onthe upstream/downstream module definition, as well as the "how/when/where/why does the Splunk UI framework dispatch searches" question.
OK. Just remove this param from your Switcher module:
<param name="requiresDispatch">True</param>
Just delete it entirely. That param is forcing a dispatch right where the Switcher is, and since there's neither a search nor a savedsearch defined upstream from that point, the framework is dispatching a "*" search over all time. Remove that one param and this dispatched search will go away. Also the removal thereof will not have any other effect on anything that I can see.
You're already using Sideview Utils 2.X (looking at your module config), and I think after this experience, you'll get a greater understanding by re-reading the "Introduction to Advanced XML" page, aka "framework_intro". It casts light onthe upstream/downstream module definition, as well as the "how/when/where/why does the Splunk UI framework dispatch searches" question.
Thanks so much.. This worked 🙂
I've pasted my xml/view
Can you post or pastebin the XML of the view? I've seen this happen several times and each case it was from the dashboard's author not fully understanding where and how the Splunk UI kicks off it's searches. By rearranging the XML we were always able to get the "*" searches to go away and I strongly suspect we can do the same thing here.