<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upgrade and My Dashboard is broke from DataInputs/Fields in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516726#M34586</link>
    <description>&lt;P&gt;I upgraded a minor version recently and my data inputs and field extractions are removed. So my dashboard no longer works. Is this normal for upgrades? Also how can I link them back so in the dashboards or the search the fields are properly extracted?&lt;/P&gt;</description>
    <pubDate>Fri, 28 Aug 2020 14:44:01 GMT</pubDate>
    <dc:creator>jenkinsta</dc:creator>
    <dc:date>2020-08-28T14:44:01Z</dc:date>
    <item>
      <title>Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516726#M34586</link>
      <description>&lt;P&gt;I upgraded a minor version recently and my data inputs and field extractions are removed. So my dashboard no longer works. Is this normal for upgrades? Also how can I link them back so in the dashboards or the search the fields are properly extracted?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 14:44:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516726#M34586</guid>
      <dc:creator>jenkinsta</dc:creator>
      <dc:date>2020-08-28T14:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516733#M34588</link>
      <description>&lt;P&gt;No this is not a normal. Basically there are two reason what came my mind.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;You have manually put your changes under default folder instead of use local folders.&lt;/LI&gt;&lt;LI&gt;Your update has contains rm -fr SPLUNK_DIR or something else which has removed those local folders.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 14:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516733#M34588</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-28T14:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516739#M34589</link>
      <description>That's not normal unless you created your data inputs and field extractions by modifying files in $SPLUNK_HOME/etc/system/default.&lt;BR /&gt;What did you upgrade from and to?</description>
      <pubDate>Fri, 28 Aug 2020 14:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516739#M34589</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-28T14:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516745#M34590</link>
      <description>&lt;P&gt;I migrated to&amp;nbsp;VERSION=8.0.5 from the previous version I downloaded in May 2020.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing was unique from this installation. I had the trial and now the free limited version which I upgraded the same time my trial expired and got my free version license.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have several folders on my linux box with data inputs for some logging like my current wifi, current temp, remote ip, internet speed. I used the input wizard and extracted fields then took that search and created dashboard panels. After the upgrade and licence change it got disconnected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 15:13:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516745#M34590</guid>
      <dc:creator>jenkinsta</dc:creator>
      <dc:date>2020-08-28T15:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516746#M34591</link>
      <description>&lt;P&gt;This sound weird.&lt;/P&gt;&lt;P&gt;Can you see if there is something related to this on migration.log-xxxx.xxx file under var/log/splunk.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 15:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516746#M34591</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-28T15:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516769#M34592</link>
      <description>&lt;P&gt;migration.log.2020-07-30.12-07-30&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 16:33:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516769#M34592</guid>
      <dc:creator>jenkinsta</dc:creator>
      <dc:date>2020-08-28T16:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516770#M34593</link>
      <description>&lt;P&gt;Migrating to:&lt;BR /&gt;VERSION=8.0.5&lt;BR /&gt;BUILD=a1a6394cc5ae&lt;BR /&gt;PRODUCT=splunk&lt;BR /&gt;PLATFORM=Linux-x86_64&lt;/P&gt;&lt;P&gt;Copying '/opt/splunk/etc/myinstall/splunkd.xml' to '/opt/splunk/etc/myinstall/splunkd.xml-migrate.bak'.&lt;/P&gt;&lt;P&gt;Checking saved search compatibility...&lt;/P&gt;&lt;P&gt;Checking for possible timezone configuration errors...&lt;/P&gt;&lt;P&gt;Handling deprecated files...&lt;/P&gt;&lt;P&gt;Checking script configuration...&lt;/P&gt;&lt;P&gt;Copying '/opt/splunk/etc/myinstall/splunkd.xml.cfg-default' to '/opt/splunk/etc/myinstall/splunkd.xml'.&lt;BR /&gt;Deleting '/opt/splunk/etc/system/local/field_actions.conf'.&lt;/P&gt;&lt;P&gt;The following apps might contain lookup table files that are not exported to other apps:&lt;/P&gt;&lt;P&gt;departures-board-viz&lt;BR /&gt;event-timeline-viz&lt;BR /&gt;heat-map-viz&lt;BR /&gt;missile_map&lt;BR /&gt;network-diagram-viz&lt;BR /&gt;splunk_monitoring_console&lt;/P&gt;&lt;P&gt;Such lookup table files could only be used within their source app. To export them globally and allow other apps to access them, add the following stanza to each /opt/splunk/etc/apps/&amp;lt;app_name&amp;gt;/metadata/local.meta file:&lt;/P&gt;&lt;P&gt;[lookups]&lt;BR /&gt;export = system&lt;/P&gt;&lt;P&gt;For more information, see &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/SetPermissions#Make_objects_globally_available" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/SetPermissions#Make_objects_globally_available&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Checking for possible UI view conflicts...&lt;BR /&gt;App "splunk_monitoring_console" has an overriding copy of the "dashboards.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views&lt;BR /&gt;App "splunk_monitoring_console" has an overriding copy of the "reports.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views&lt;BR /&gt;App "splunk_monitoring_console" has an overriding copy of the "alerts.xml" view, thus the new version may not be in effect. location=/opt/splunk/etc/apps/splunk_monitoring_console/default/data/ui/views&lt;BR /&gt;Removing legacy manager XML files...&lt;BR /&gt;Removing legacy nav XML files...&lt;BR /&gt;DMC is not set up, no need to migrate nav bar.&lt;BR /&gt;Removing System Activity dashboards...&lt;BR /&gt;Removing splunkclouduf XML file...&lt;BR /&gt;Removing splunkclouduf view XML files...&lt;BR /&gt;Distributed Search is not configured on this instance&lt;BR /&gt;Removing legacy search.xml file from splunk_instrumentation...&lt;BR /&gt;Deleting '/opt/splunk/share/splunk/search_mrsparkle/modules'.&lt;BR /&gt;Moving '/opt/splunk/share/splunk/search_mrsparkle/modules.new' to '/opt/splunk/share/splunk/search_mrsparkle/modules'.&lt;/P&gt;&lt;P&gt;Checking for the modules related files and folders that should not be present after upgrade.&lt;/P&gt;&lt;P&gt;Checking for the Advanced XML dashboard templates that should not be present after upgrade.&lt;/P&gt;&lt;P&gt;Checking for the 'Getting Started' app that should not be present after upgrade.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It seems that the Splunk default certificates are being used. If certificate validation is turned on using the default certificates (not-recommended), this may result in loss of communication in mixed-version Splunk environments after upgrade.&lt;/P&gt;&lt;P&gt;"/opt/splunk/etc/auth/ca.pem": already a renewed Splunk certificate: skipping renewal&lt;BR /&gt;"/opt/splunk/etc/auth/cacert.pem": already a renewed Splunk certificate: skipping renewal&lt;BR /&gt;Clustering migration already complete, no further changes required.&lt;/P&gt;&lt;P&gt;Generating checksums for datamodel and report acceleration bucket summaries for all indexes.&lt;BR /&gt;If you have defined many indexes and summaries, summary checksum generation may take a long time.&lt;BR /&gt;Processed 1 out of 12 configured indexes.&lt;BR /&gt;Processed 2 out of 12 configured indexes.&lt;BR /&gt;Processed 3 out of 12 configured indexes.&lt;BR /&gt;Processed 4 out of 12 configured indexes.&lt;BR /&gt;Processed 5 out of 12 configured indexes.&lt;BR /&gt;Processed 6 out of 12 configured indexes.&lt;BR /&gt;Processed 7 out of 12 configured indexes.&lt;BR /&gt;Processed 8 out of 12 configured indexes.&lt;BR /&gt;Processed 9 out of 12 configured indexes.&lt;BR /&gt;Processed 10 out of 12 configured indexes.&lt;BR /&gt;Processed 11 out of 12 configured indexes.&lt;BR /&gt;Processed 12 out of 12 configured indexes.&lt;BR /&gt;Finished generating checksums for datamodel and report acceleration bucket summaries for all indexes.&lt;BR /&gt;[App Key Value Store migration] Checking if migration is needed. Upgrade type 1. This can take up to 600 seconds.&lt;BR /&gt;[App Key Value Store migration] Migration is not required.&lt;BR /&gt;[App Key Value Store migration] Checking if migration is needed. Upgrade type 2. This can take up to 600 seconds.&lt;BR /&gt;[App Key Value Store migration] Migration is not required.&lt;BR /&gt;[DFS] Performing migration.&lt;BR /&gt;[DFS] Finished migration.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 16:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516770#M34593</guid>
      <dc:creator>jenkinsta</dc:creator>
      <dc:date>2020-08-28T16:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516772#M34594</link>
      <description>&lt;P&gt;Unfortunately at least I cannot see anything special which related to your problem.&lt;/P&gt;&lt;P&gt;One another place which you could check is root's history if there is any commands wihch can explain this? Otherwise it's hard (/impossible) said what was caused that unnormal behaviour.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 16:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516772#M34594</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-28T16:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516773#M34595</link>
      <description>&lt;P&gt;Ok, thanks for the help. Not a big deal if a one off. But I don't want to rebuild every time.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 16:50:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516773#M34595</guid>
      <dc:creator>jenkinsta</dc:creator>
      <dc:date>2020-08-28T16:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516775#M34597</link>
      <description>Don't rebuild - restore your latest backup.&lt;BR /&gt;If you put your dashboards and other knowledge objects in a custom app then backup and restore of that app is trivial. It's also a recommended part of the upgrade process.</description>
      <pubDate>Fri, 28 Aug 2020 17:03:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516775#M34597</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-28T17:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516779#M34599</link>
      <description>&lt;P&gt;I think I see the problem. During the trial I created these things under a user i created or admin. Since I downgraded there is no user. I changed all the permissions/owner to nobody but not sure where else I need to change. But my newly created items are listed as nobody as the owner.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 17:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516779#M34599</guid>
      <dc:creator>jenkinsta</dc:creator>
      <dc:date>2020-08-28T17:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516783#M34601</link>
      <description>&lt;P&gt;That’s true. In trial you could use several users and another features which is not usable on free version. That’s said on documentation too.&amp;nbsp;&lt;BR /&gt;In your case you probably found those KOs on disk if you look those on under etc.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 17:36:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516783#M34601</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-08-28T17:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade and My Dashboard is broke from DataInputs/Fields</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516786#M34602</link>
      <description>That should be easy to fix. Go to the CLI and move files from $SPLUNK_HOME/etc/users/&amp;lt;user&amp;gt; to $SPLUNK_HOME/etc/users/admin. Then restart Splunk.</description>
      <pubDate>Fri, 28 Aug 2020 18:14:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Upgrade-and-My-Dashboard-is-broke-from-DataInputs-Fields/m-p/516786#M34602</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-28T18:14:48Z</dc:date>
    </item>
  </channel>
</rss>

