In SQL-speak, "how to specify the columns in
SELECT clause"? Normally, Splunk does the equivalent of
SELECT *, which might not be wanted.
_* refers to the reserved (a.k.a. "internal") fields such as _time.
So it seems to read "I want foo, and I don't want any internal fields".
The explanation at http://www.splunk.com/base/Documentation/latest/SearchReference/Fields might make more sense to you.