- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Add-on for OSSEC: Why are my pre-built panels gone after update?
Updated and the pre-built panels are gone....how do I get them back?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm having the same problem as jchamb above. I just installed Splunk 6.5.0 and all the dropdowns are gone and there is no functionality. I have no dashboards, reports metrics, etc. The only drop down is for "Default View". "Dashboards and Views", "Searches and Reports" and "Agent Management" are all gone.
Here's a pic:
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

I still see the pre-built panels are still part of the TA under Splunk_TA_ossec/default/data/ui/panels/. You should not lose any dashboard built using those panels unless you have them saved in the default folder.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
so I have 4 files in that directory. However when I click on the app in splunk the only drop down menu is "default" where there used to be quite a few others...
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

maybe your dashboard doesnt have permission to the OSSEC app? It works on my end which means could be permission. Either check permission or more those panels to the app that contains the dashboard in question
