Dashboards & Visualizations

If a someone reruns a script to get an output that replaces the old file, will my dashboard only include new information, or will the old information stay indexed?

alanxu
Communicator

Hello Everyone,

I presented my project to my team and one coworker had a few concerns about my dashboard.

1) If they rerun a script to get an output that replaces the old file, will my dashboard only include the new information? Or does the old information stay indexed even though the file was deleted?

And thank you Splunk Community with helping me these past weeks!

0 Karma
1 Solution

jensonthottian
Contributor

1) If they rerun a script to get an output that replaces the old file. Will my dashboard only include the new information? Or does the old information stay indexed even though the file was deleted -

Is this output an CSV which is imported in Splunk? if yes then you will only have new CSV information at your disposal.
Is this output a text file which is forwarded to Splunk indexer? If yes, then if the old text file is forwarded to Splunk indexer before it is replaced by a new file you will have both old and new file at your disposal with different timestamps.

2) If my account is deleted so are my alerts and dashboards?

If your account is deleted all your private alerts and dashboards are not deleted. Since those are set as "private" permission, can be accessed and edited by an admin.

View solution in original post

jensonthottian
Contributor

1) If they rerun a script to get an output that replaces the old file. Will my dashboard only include the new information? Or does the old information stay indexed even though the file was deleted -

Is this output an CSV which is imported in Splunk? if yes then you will only have new CSV information at your disposal.
Is this output a text file which is forwarded to Splunk indexer? If yes, then if the old text file is forwarded to Splunk indexer before it is replaced by a new file you will have both old and new file at your disposal with different timestamps.

2) If my account is deleted so are my alerts and dashboards?

If your account is deleted all your private alerts and dashboards are not deleted. Since those are set as "private" permission, can be accessed and edited by an admin.

alanxu
Communicator

It is an output text file that is automatically indexed in Splunk.

And the alerts and dashboards are in the app now.

Thank you for your answer

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...