Dashboards & Visualizations

Dashboard display could not find object id= after migrating in 7.2.3

sebgirardlux
New Member

I've upgrade Splunk Enterprise in 7.2.3, everything went well. I opened the dashboard and have on most of my dashboard the message could not find object id= ....
I have all the rights and honestly I'm stuck, does anyone can help?
Thanks

Tags (1)
0 Karma
1 Solution

dkeck
Influencer

Hi,

are you able to create new dashboards?

There was a bug in earlier 6.x versions where users couldn´t create dashboards with error like you have. Might be related?!

View solution in original post

0 Karma

dkeck
Influencer

Hi,

are you able to create new dashboards?

There was a bug in earlier 6.x versions where users couldn´t create dashboards with error like you have. Might be related?!

0 Karma

sebgirardlux
New Member

Hi,

yes I'm able to create dashboard.
I think it is related with the scheduled reports but I do not understand.
I used to created my dashboard with reports but I don't find my report since the upgrade...

[CustomerX Deep Security Malware Event]
action.email.useNSSubject = 1
alert.track = 0
dispatch.earliest_time = -30d@d
dispatch.latest_time = now
display.events.fields = ["host","source","sourcetype","Domain","cef_severity"]
display.general.type = visualizations
display.page.search.mode = verbose
display.page.search.tab = visualizations
display.statistics.show = 0
display.visualizations.charting.chart.stackMode = stacked
display.visualizations.charting.chart.style = minimal
request.ui_dispatch_app = search
request.ui_dispatch_view = search
search = index=xxx_antimalware product="Deep Security Manager" cef_rulename="Alert Started" msg="Alert: Anti-Malware Alert*" "customerX_*" | timechart count by target

0 Karma

dkeck
Influencer

Ok if you can´t find objects after a splunk upgrade thats sounds like they where somehow created in default before the update?? This would explain why they are missing now. Default is overwritten after an upgrade

0 Karma

sebgirardlux
New Member

well i have to recreate the daashboard then... 😞

0 Karma

dkeck
Influencer

I would be happy if you could accept and upvote the answer 🙂

0 Karma

dkeck
Influencer

sry to hear that, but you are not suppost to create objects in default. Always use local.

Maybe you backup your splunk folder somewhere with your server backup? maybe you can find them there.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...