The first thing to note about form dashboard optimizations is that the closer to the root search you can place tokens, the faster your searches will go, meaning that if we use our dashboard inputs to place tokens such as host source, source type, eventtype, or tag within the root search, then we will increase the performance of our searches.
For instance, let's take some dashboards from an app and break them down. I am going to choose the Citrix netscaler app because it's simplistic enough in nature. I'm going to use the Load Balancing Dashboard as the single page of focus within this app.
https://splunkbase.splunk.com/app/370/
The dashboard looks like the following screenshot:
Note
Notice that, when we start delving into each of the modules, there are three text inputs, one time input, and a single Submit button at the top of the page. I will focus on the text inputs and the tokens they are passing for now.
Looking closer at each input, you will notice that each token has...