All Apps and Add-ons

What will be the effect on customization if i update an app from the market. Will it be gone .If yes how can i restore the the customization of the previous app?

kartik13
Communicator

I am currenty doing some work in ISE app oon the previous version i, i have customized my searches and dashboards. If i update to a new version will my customizations will be gone . if yes how can i restore my previous customizations .

0 Karma
1 Solution

jconger
Splunk Employee
Splunk Employee

How have you customized your searches and dashboards?

If you are editing the actual XML files located in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/default/data/ui/views, then yes, your customizations will be wiped out on an upgrade.

If you want to directly edit the XML files, you should first make a copy of the dashboard's XML file and pace it in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/local/data/ui/views (notice local in the path instead of default).

If you are not directly editing the XML and just using the Splunk web interface to make changes, you should be fine.

View solution in original post

jconger
Splunk Employee
Splunk Employee

How have you customized your searches and dashboards?

If you are editing the actual XML files located in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/default/data/ui/views, then yes, your customizations will be wiped out on an upgrade.

If you want to directly edit the XML files, you should first make a copy of the dashboard's XML file and pace it in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/local/data/ui/views (notice local in the path instead of default).

If you are not directly editing the XML and just using the Splunk web interface to make changes, you should be fine.

kartik13
Communicator

hi,

so for the config files also i have to follow the same process. i.e. backing up those files

0 Karma

jconger
Splunk Employee
Splunk Employee

As long as you do not overwrite $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/default, you should be okay. Make your changes in $SPLUNK_HOME/etc/apps/Splunk_CiscoISE/local instead.

Splunk combines the contents/configurations of default and local. If a setting is defined in both default and local, the setting in local will win. New apps and upgraded apps ship without content in local for this reason.

0 Karma

markthompson
Builder

Hello @kartik13
I should imagine as its a dashboard all you need to do is find where its saved, and take a backup of the XML files.

Maybe @ppablo_splunk will be able to help with this.

Like I say, I should imagine it's the same as any normal dashboard where it stores it's dashboards in XML files, which you should just be able to copy / save to a different location.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...