I'm creating some dashboards for use by our entire development team. Basically, it's a set of 7 saved searches displayed as pretty little bar charts or line graphs. None of them are real-time searches. If 20 people suddenly decide to load the dashboard at the same time, does this put a load of 140 searches on Splunk all at the same time?
Is there a way to make the dashboard simply display the last result of that saved search? I could easily schedule these searches to run once an hour if that would reduce load on the search heads when lots of developers fire up Splunk each morning.
By default, a dashboard will use saved results of a scheduled search, if in fact the panel is built referencing the scheduled search, and if the security of the search is set so that the users can see the search.