Just wondering when looking into performance improvements... After logging in to Splunk (, you see on the right some fancy statistics that are interesting for the first times, but after that makes one wonder... Like:

Events Indexed: 7,725,934,214
Earliest Event: 6 years ago
Latest Event: Now

It keeps on updating the numbers for quite some time, giving the impression doing some background query.
Not relevant for all users. So: anyone any knowledge of the load this causes as every user gets this?

Can this be disabled for all users and how?

The load generated by this is very low - it's not actually looking at those seven billion events but only at counters / meta-data.

