Dashboards & Visualizations

If a someone reruns a script to get an output that replaces the old file, will my dashboard only include new information, or will the old information stay indexed?

alanxu
Communicator

Hello Everyone,

I presented my project to my team and one coworker had a few concerns about my dashboard.

1) If they rerun a script to get an output that replaces the old file, will my dashboard only include the new information? Or does the old information stay indexed even though the file was deleted?

And thank you Splunk Community with helping me these past weeks!

0 Karma
1 Solution

jensonthottian
Contributor

1) If they rerun a script to get an output that replaces the old file. Will my dashboard only include the new information? Or does the old information stay indexed even though the file was deleted -

Is this output an CSV which is imported in Splunk? if yes then you will only have new CSV information at your disposal.
Is this output a text file which is forwarded to Splunk indexer? If yes, then if the old text file is forwarded to Splunk indexer before it is replaced by a new file you will have both old and new file at your disposal with different timestamps.

2) If my account is deleted so are my alerts and dashboards?

If your account is deleted all your private alerts and dashboards are not deleted. Since those are set as "private" permission, can be accessed and edited by an admin.

View solution in original post

jensonthottian
Contributor

1) If they rerun a script to get an output that replaces the old file. Will my dashboard only include the new information? Or does the old information stay indexed even though the file was deleted -

Is this output an CSV which is imported in Splunk? if yes then you will only have new CSV information at your disposal.
Is this output a text file which is forwarded to Splunk indexer? If yes, then if the old text file is forwarded to Splunk indexer before it is replaced by a new file you will have both old and new file at your disposal with different timestamps.

2) If my account is deleted so are my alerts and dashboards?

If your account is deleted all your private alerts and dashboards are not deleted. Since those are set as "private" permission, can be accessed and edited by an admin.

alanxu
Communicator

It is an output text file that is automatically indexed in Splunk.

And the alerts and dashboards are in the app now.

Thank you for your answer

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...