All Apps and Add-ons

What will be the effect on customization if i update an app from the market. Will it be gone .If yes how can i restore the the customization of the previous app?

kartik13
Communicator

I am currenty doing some work in ISE app oon the previous version i, i have customized my searches and dashboards. If i update to a new version will my customizations will be gone . if yes how can i restore my previous customizations .

0 Karma
1 Solution

jconger
Splunk Employee
Splunk Employee

How have you customized your searches and dashboards?

If you are editing the actual XML files located in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/default/data/ui/views, then yes, your customizations will be wiped out on an upgrade.

If you want to directly edit the XML files, you should first make a copy of the dashboard's XML file and pace it in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/local/data/ui/views (notice local in the path instead of default).

If you are not directly editing the XML and just using the Splunk web interface to make changes, you should be fine.

View solution in original post

jconger
Splunk Employee
Splunk Employee

How have you customized your searches and dashboards?

If you are editing the actual XML files located in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/default/data/ui/views, then yes, your customizations will be wiped out on an upgrade.

If you want to directly edit the XML files, you should first make a copy of the dashboard's XML file and pace it in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/local/data/ui/views (notice local in the path instead of default).

If you are not directly editing the XML and just using the Splunk web interface to make changes, you should be fine.

kartik13
Communicator

hi,

so for the config files also i have to follow the same process. i.e. backing up those files

0 Karma

jconger
Splunk Employee
Splunk Employee

As long as you do not overwrite $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/default, you should be okay. Make your changes in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/local instead.

Splunk combines the contents/configurations of default and local. If a setting is defined in both default and local, the setting in local will win. New apps and upgraded apps ship without content in local for this reason.

0 Karma

markthompson
Builder

Hello @kartik13
I should imagine as its a dashboard all you need to do is find where its saved, and take a backup of the XML files.

Maybe @ppablo_splunk will be able to help with this.

Like I say, I should imagine it's the same as any normal dashboard where it stores it's dashboards in XML files, which you should just be able to copy / save to a different location.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...