Dashboards & Visualizations

Is it possible to copy savedsearches.conf from an old Splunk app to a recent one (newest Splunk version)?

skender27
Contributor

Hi,

The requirement is to have the same dashboard (lots of href links to searches in Splunk organized in blockes) when building up a new Splunk distributed platform.

I am thinking to reuse the same savedsearches.conf (a large one made in html) from a Splunk 5.0.9 to a recent version and so copying it under the same app local folder...
What issues should I consider (except removing the vsid row from each search saved)?

Thanks a lot,
Skender

0 Karma

somesoni2
Revered Legend

You would need to copy the savedsearches.conf and corresponding local.meta entries (yourApp/metadata folder). The local.meta would define the permissions and scope (visibility) for the searches (required).

skender27
Contributor

Unfortunatelly no (should I override the existing folder?).

In fact, it is unnecessary now because some of them are obsolete . Well in this case I think I have to re-create all the searches which feed the href links of the dashboard.

I will let you know,
Skender

0 Karma

skender27
Contributor

Hi,

I tried deleting the vsid attributes from the copied savedsearches.conf, but still i couldn't get the old searches.
Probably because of different Splunk versions: the old one was a Enterprise 5.0.8 and the new one was a 6.4.
Could it be the reason?

Skender

0 Karma

somesoni2
Revered Legend

And did you copy the .meta entries as well?

0 Karma

skender27
Contributor

Sure, I will try next week and I'll share how this behaves.

Thanks a lot,
Skender

0 Karma

skender27
Contributor

Precision: "a large one made in html" I mean the dashboard, not the .conf file.

Skender

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Yes, Should be perfectly fine. Give it a try and let me know the results.

skender27
Contributor

I can try this only the next week...
I will share all the results about this issue.

Thanks,
Skender

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...