Hello,
we are very new to Splunk. At the moment we try the palo alto app and missed some inputs on dashboards for search and filter.
Whats the best way to extend this app but do it so, that after an upgrade of the app, the changes will not be lost?
Is it ok to copy the view from default to local folder and do the changes ? Will it persist after an upgrade of the app?
Hi
i haven’t seen any real officially supported way to do this. With most apps probably the easiest way is to use your own git repository where you keep official codes and own branch for your own changes/modifications. When a new version has published then just merge your own and latest versions to your new deployable version.
r. Ismo