All Apps and Add-ons

How do I recover a dashboard in Splunk App for Amazon Web Services?

joyitadas
Engager

Hi,

While configuring the "VPC flow logs" Input on Splunk Add-on for AWS, one of my team members changed the dashboard for "VPC Flow Logs- Traffic Analysis" in Splunk App for AWS. The XML was changed accessed by the "Edit Source" button.

Now when we go on Security tab, we can see the dashboard- "VPC Flow Logs- Security Analysis" twice but no dashboard for "VPC Flow Logs - Traffic Analysis".

Is there any way I can recover the dashboard? Can you please provide the XML file for the same?
Warm Regards,
Joyita Das

0 Karma
1 Solution

traxxasbreaker
Communicator

On the Splunk server, take a look in the directory for the AWS app under $SPLUNK_HOME/etc/apps. Under default/data/ui/views you should be able to see the original dashboard XML.

If that is the case, go to the app's local/data/ui/views and copy the XML for that view from the local directory to some temporary location. Then, in your browser go to http://yoursplunkserver:8000/en-US/debug/refresh to reload. Getting rid of the version in the local directory should set what displays back to the default dashboard.

View solution in original post

traxxasbreaker
Communicator

On the Splunk server, take a look in the directory for the AWS app under $SPLUNK_HOME/etc/apps. Under default/data/ui/views you should be able to see the original dashboard XML.

If that is the case, go to the app's local/data/ui/views and copy the XML for that view from the local directory to some temporary location. Then, in your browser go to http://yoursplunkserver:8000/en-US/debug/refresh to reload. Getting rid of the version in the local directory should set what displays back to the default dashboard.

joyitadas
Engager

Thanks for the help, it worked 🙂

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...