Hi,
While configuring the "VPC flow logs" Input on Splunk Add-on for AWS, one of my team members changed the dashboard for "VPC Flow Logs- Traffic Analysis" in Splunk App for AWS. The XML was changed accessed by the "Edit Source" button.
Now when we go on Security tab, we can see the dashboard- "VPC Flow Logs- Security Analysis" twice but no dashboard for "VPC Flow Logs - Traffic Analysis".
Is there any way I can recover the dashboard? Can you please provide the XML file for the same?
Warm Regards,
Joyita Das
On the Splunk server, take a look in the directory for the AWS app under $SPLUNK_HOME/etc/apps
. Under default/data/ui/views
you should be able to see the original dashboard XML.
If that is the case, go to the app's local/data/ui/views
and copy the XML for that view from the local directory to some temporary location. Then, in your browser go to http://yoursplunkserver:8000/en-US/debug/refresh to reload. Getting rid of the version in the local directory should set what displays back to the default dashboard.
On the Splunk server, take a look in the directory for the AWS app under $SPLUNK_HOME/etc/apps
. Under default/data/ui/views
you should be able to see the original dashboard XML.
If that is the case, go to the app's local/data/ui/views
and copy the XML for that view from the local directory to some temporary location. Then, in your browser go to http://yoursplunkserver:8000/en-US/debug/refresh to reload. Getting rid of the version in the local directory should set what displays back to the default dashboard.
Thanks for the help, it worked 🙂