I'm trying to add an event view to a dashboard, but Splunk seems to ignore the options set in the XML:
<event>
<searchName>Global AAA - Failed: bad password</searchName>
<title>Mistyped Passwords</title>
<fields>User,NetworkDeviceName</fields>
<count>15</count>
<maxLines>1</maxLines>
</event>
I have also tried other variations like <option name="count">15</option>
and <event count=15>
. Every time I still get about 26 entries.