That was the answer I was looking for:
in Splunk 6, for the first method to work, you'll need to include a blank
<default></default>
Had some strange behaviour in my dashboards, because I used to make an "optional" search for a keyword appended to the base search ( | search $something$ ) - and by default, splunk <6 omitted an empty input. Now the mentioned statement brings back this behaviour - thanks for the hint 🙂
... View more