<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Edit a view from and existing app in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Edit-a-view-from-and-existing-app/m-p/57139#M3037</link>
    <description>&lt;P&gt;i have not played with the Cisco Security App, but i am assuming this app has a directory (similar to the search app) where you can go and modify what you would like.&lt;BR /&gt;
/splunk/etc/apps/search/default/data/ui/views - here you can modify the views for the search app, try locating a similar directory for the Cisco Security App and try modifying the xml files in there.&lt;/P&gt;

&lt;P&gt;Note, i would recommend making a backup to the directory before you commit any changes.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Sep 2010 01:39:15 GMT</pubDate>
    <dc:creator>Genti</dc:creator>
    <dc:date>2010-09-24T01:39:15Z</dc:date>
    <item>
      <title>Edit a view from and existing app</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Edit-a-view-from-and-existing-app/m-p/57138#M3036</link>
      <description>&lt;P&gt;I've loaded the Cisco Security App in splunk. I like some of the reports that they provide under views but I need to customize them to our needs. They don't quite extend to the time that we'd like.\&lt;/P&gt;

&lt;P&gt;Under the actions menu the edit optioon is not available like it is with a typical view and dashboard.&lt;/P&gt;

&lt;P&gt;How can I edit these?&lt;/P&gt;

&lt;P&gt;I've already been down the road of app permission, dashboard permissions.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 00:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Edit-a-view-from-and-existing-app/m-p/57138#M3036</guid>
      <dc:creator>strueblood</dc:creator>
      <dc:date>2010-09-24T00:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Edit a view from and existing app</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Edit-a-view-from-and-existing-app/m-p/57139#M3037</link>
      <description>&lt;P&gt;i have not played with the Cisco Security App, but i am assuming this app has a directory (similar to the search app) where you can go and modify what you would like.&lt;BR /&gt;
/splunk/etc/apps/search/default/data/ui/views - here you can modify the views for the search app, try locating a similar directory for the Cisco Security App and try modifying the xml files in there.&lt;/P&gt;

&lt;P&gt;Note, i would recommend making a backup to the directory before you commit any changes.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 01:39:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Edit-a-view-from-and-existing-app/m-p/57139#M3037</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-09-24T01:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Edit a view from and existing app</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Edit-a-view-from-and-existing-app/m-p/57140#M3038</link>
      <description>&lt;P&gt;The Edit links in the actions menu are only available for views written in Splunk's  'simplified XML'.   The simplified XML is just a sort of macro or shorthand way of writing a view in the underlying 'advanced XML',  and most or quite possibly all of the Cisco app's views are written in the advanced XML. &lt;/P&gt;

&lt;P&gt;However you can go to Manager,  User Interface,  Views,  and edit any view you see there. &lt;/P&gt;

&lt;P&gt;When you save that edited version,  Splunk will create a copy of that view at &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&amp;lt;splunkHome&amp;gt;/etc/apps/&amp;lt;appName&amp;gt;/local/data/ui/views&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;and the local vs system distinction should call to mind splunk's layered system for conf files, because that's how it works -- the version of the view in local will override the version in system.   &lt;/P&gt;

&lt;P&gt;I do not recommend editing the version in the system folder because if and when you upgrade the cisco app to a newer version, your changes would be clobbered. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 03:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Edit-a-view-from-and-existing-app/m-p/57140#M3038</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2010-09-24T03:08:30Z</dc:date>
    </item>
  </channel>
</rss>

