Dashboards & Visualizations

Is it possible to copy savedsearches.conf from an old Splunk app to a recent one (newest Splunk version)?

skender27
Contributor

Hi,

The requirement is to have the same dashboard (lots of href links to searches in Splunk organized in blockes) when building up a new Splunk distributed platform.

I am thinking to reuse the same savedsearches.conf (a large one made in html) from a Splunk 5.0.9 to a recent version and so copying it under the same app local folder...
What issues should I consider (except removing the vsid row from each search saved)?

Thanks a lot,
Skender

0 Karma

somesoni2
Revered Legend

You would need to copy the savedsearches.conf and corresponding local.meta entries (yourApp/metadata folder). The local.meta would define the permissions and scope (visibility) for the searches (required).

skender27
Contributor

Unfortunatelly no (should I override the existing folder?).

In fact, it is unnecessary now because some of them are obsolete . Well in this case I think I have to re-create all the searches which feed the href links of the dashboard.

I will let you know,
Skender

0 Karma

skender27
Contributor

Hi,

I tried deleting the vsid attributes from the copied savedsearches.conf, but still i couldn't get the old searches.
Probably because of different Splunk versions: the old one was a Enterprise 5.0.8 and the new one was a 6.4.
Could it be the reason?

Skender

0 Karma

somesoni2
Revered Legend

And did you copy the .meta entries as well?

0 Karma

skender27
Contributor

Sure, I will try next week and I'll share how this behaves.

Thanks a lot,
Skender

0 Karma

skender27
Contributor

Precision: "a large one made in html" I mean the dashboard, not the .conf file.

Skender

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Yes, Should be perfectly fine. Give it a try and let me know the results.

skender27
Contributor

I can try this only the next week...
I will share all the results about this issue.

Thanks,
Skender

0 Karma
Get Updates on the Splunk Community!

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...