What is the best practice for migrating dashboards from one system to another.

Splunk Employee

Current is 6.6.4 and new system is 7.0. The issue we have is that the entire knowledge object is not migrating. Example would be a custom transform, search or tag. The xml file is easy enough but not all the KO.

I don't think there should be any compatibility issues between 6.6 and 7.0.

Are you sure all the KO objects are in the app you are moving? - its easy to overlook a few extractions, tags and aliases in the search app which have been made global instead of app specific instead of in your target app.

Your best bet is to view all your config items, app by app, and move any which are in the wrong place.

Also - try installing the add-on builder app - from that tool you can download your app and it will merge you default & local configs into just default - obviously worth testing fully, but I have done exactly the same as you with good results in the past.

