Dashboards & Visualizations

Migrating chart settings from 3.4 -> 4.x: possible?

Jason
Motivator

Is it possible to migrate saved searches' view settings (such as open as a chart, not in search view - and here are the chart settings) when migrating from 3.4.x to 4.1.x?

The client has a lot of saved searches in 3, and while they work in 4, they look nothing like they are supposed to. It's going to be very annoying if we (I) have to have a 3.x version open and a 4.x version open, trying to make one look like the other manually!

I thought auto-migrate moved viewstate.* to the viewstates.conf file, not just commented them out and deleted them...

Tags (2)
0 Karma
1 Solution

Mick
Splunk Employee
Splunk Employee

Migration of views and dashboards from 3.x to 4.x was not easily and reliably achievable with a scripted solution. The changes in the UI were just too fast, and the new options too many for us to be able to reproduce exactly what was needed. Also, the UI was completely re-written so that it's now infinitely flexible and can display data any way you want, so this was also looked on as an opportunity to get people to build new dashboards and get familiar with the new UI.

The basic UI dashboard builder is pretty striaghforward if your searches aren't too complicated - http://www.splunk.com/base/Documentation/latest/User/CreateSimpleDashboards - just remember that any charts you build are driven by the search itself rather than the actual dashboard XML.

If more advanced dashboards are required, you'll just have to get your hands dirty with the XML.

View solution in original post

0 Karma

Mick
Splunk Employee
Splunk Employee

Migration of views and dashboards from 3.x to 4.x was not easily and reliably achievable with a scripted solution. The changes in the UI were just too fast, and the new options too many for us to be able to reproduce exactly what was needed. Also, the UI was completely re-written so that it's now infinitely flexible and can display data any way you want, so this was also looked on as an opportunity to get people to build new dashboards and get familiar with the new UI.

The basic UI dashboard builder is pretty striaghforward if your searches aren't too complicated - http://www.splunk.com/base/Documentation/latest/User/CreateSimpleDashboards - just remember that any charts you build are driven by the search itself rather than the actual dashboard XML.

If more advanced dashboards are required, you'll just have to get your hands dirty with the XML.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...