I am currenty doing some work in ISE app oon the previous version i, i have customized my searches and dashboards. If i update to a new version will my customizations will be gone . if yes how can i restore my previous customizations .
I should imagine as its a dashboard all you need to do is find where its saved, and take a backup of the XML files.
Maybe @ppablo_splunk will be able to help with this.
Like I say, I should imagine it's the same as any normal dashboard where it stores it's dashboards in XML files, which you should just be able to copy / save to a different location.
How have you customized your searches and dashboards?
If you are editing the actual XML files located in $SPLUNKHOME/etc/apps/SplunkCiscoISE/default/data/ui/views, then yes, your customizations will be wiped out on an upgrade.
If you want to directly edit the XML files, you should first make a copy of the dashboard's XML file and pace it in $SPLUNKHOME/etc/apps/SplunkCiscoISE/local/data/ui/views (notice local in the path instead of default).
If you are not directly editing the XML and just using the Splunk web interface to make changes, you should be fine.
so for the config files also i have to follow the same process. i.e. backing up those files
As long as you do not overwrite $SPLUNKHOME/etc/apps/SplunkCiscoISE/default, you should be okay. Make your changes in $SPLUNKHOME/etc/apps/SplunkCiscoISE/local instead.
Splunk combines the contents/configurations of default and local. If a setting is defined in both default and local, the setting in local will win. New apps and upgraded apps ship without content in local for this reason.