All Apps and Add-ons

How do I recover a dashboard in Splunk App for Amazon Web Services?

joyitadas
Engager

Hi,

While configuring the "VPC flow logs" Input on Splunk Add-on for AWS, one of my team members changed the dashboard for "VPC Flow Logs- Traffic Analysis" in Splunk App for AWS. The XML was changed accessed by the "Edit Source" button.

Now when we go on Security tab, we can see the dashboard- "VPC Flow Logs- Security Analysis" twice but no dashboard for "VPC Flow Logs - Traffic Analysis".

Is there any way I can recover the dashboard? Can you please provide the XML file for the same?
Warm Regards,
Joyita Das

0 Karma
1 Solution

traxxasbreaker
Communicator

On the Splunk server, take a look in the directory for the AWS app under $SPLUNK_HOME/etc/apps. Under default/data/ui/views you should be able to see the original dashboard XML.

If that is the case, go to the app's local/data/ui/views and copy the XML for that view from the local directory to some temporary location. Then, in your browser go to http://yoursplunkserver:8000/en-US/debug/refresh to reload. Getting rid of the version in the local directory should set what displays back to the default dashboard.

View solution in original post

traxxasbreaker
Communicator

On the Splunk server, take a look in the directory for the AWS app under $SPLUNK_HOME/etc/apps. Under default/data/ui/views you should be able to see the original dashboard XML.

If that is the case, go to the app's local/data/ui/views and copy the XML for that view from the local directory to some temporary location. Then, in your browser go to http://yoursplunkserver:8000/en-US/debug/refresh to reload. Getting rid of the version in the local directory should set what displays back to the default dashboard.

joyitadas
Engager

Thanks for the help, it worked 🙂

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...