Dashboards & Visualizations

Adding Existing Dashboards and Reports to a New App

aferone
Builder

I have a collection of dashboards, powered by saved scheduled searches, that I would like to organize into a new app. I've read over the documentation of creating a new app. However, I can't seem to get things running as they should.

Whenever I copy the views into the proper directory of the new app, and place the saved searches into "savedsearches.conf", I get all kinds of errors saying the searches can't be found.

Then, when I create a new dashboard and reports from scratch, they show up through the GUI for views and searches, but I can't find the through the CLI!

This is getting frustrating. Help!!

Tags (2)

aferone
Builder

Yeah, I checked that link out. But it keep referring to the files in the app. I can't find any of my searches in my app directory to remove those vsid entries.

0 Karma

somesoni2
Revered Legend

Ideally they should be. Confirm from UI that they are under correct app.

For view state error, visit this.
http://answers.splunk.com/answers/22779/unable-to-get-viewstate-information

0 Karma

aferone
Builder

I did both views and searches, yes. Now, I am getting the "Unable to get viewstate information; formatting may not be correct" error.

The problem is again that I can't find the searches in the app directory structure to remove the vsid entries. Shouldn't they be in the app directory structure of my app?

0 Karma

somesoni2
Revered Legend

When you change the sharing permission to 'This App' from private, they should be available in etc/apps/myapp/local. Hope you're cloning both Searches and views and will change permission for both.

0 Karma

aferone
Builder

Will they end up in the app at some point? Even when I shared them out to the app, I don't see any instances of the searches within the directory structure of the app in the CLI ($SPLUNKHOME$/etc/apps/myapp

0 Karma

somesoni2
Revered Legend

All cloned objects will be private by default. They should be present under etc/users//

0 Karma

aferone
Builder

OK, I have cloned my reports to the dashboard, and that seems to work. However, in looking through the CLI, I can't seem to find where the new cloned files are placed. Where would they be?

0 Karma

aferone
Builder

No, I haven't been restarting my search head. Do I need to?

And for cloning, how do I control which app they go to?

0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

Check permissions on all of the components (dashboards, saved searches, etc). This might be easier via the web interface but you can also lookup in <app_name>/metadata/local.meta

sbrant_splunk
Splunk Employee
Splunk Employee

It's essentially setting scope, as well as editing permissions to read/write. You can look under "settings -> searches and reports" and check sharing to edit what those settings are. For dashboards, there is no scope, just read/write, check under "settings -> user interface -> views".

0 Karma

aferone
Builder

I know I can control permissions through roles, but I was unclear with how to do it for apps?

0 Karma

somesoni2
Revered Legend

Are you doing a splunk refresh or restart after copying view xml files and copying savedsearches.conf file?? Also, it would be a better idea to clone the objects required into your new app from GUI itself.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...