Dashboards & Visualizations

Why cant I delete deprecated 'advanced XML' dashboards from Search Head Cluster?

jtfuguet
New Member

Running the SCMA app pre-migration checks in preparation for moving our environment to Cloud, we were notified of a number of old dashboards floating around using deprecated 'Advanced XML'. As most or all of these are no longer needed, I made the decision to delete these. However, it appears that the Search and Reporting app (where most of these dashboards reside) is not managed by our SHC deployer, and the old dashboards themselves cannot be deleted from the GUI settings > user interface > views. As shown below, most dashboards (top) have a Delete option, but none of the AXML dashboards allow this action. 

 

evidence.png

 

Other than manually 'rm -rf'ing on the backend for all our search heads, is there another way I can easily delete these dashboards?

Labels (1)
Tags (3)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the dashboards somehow found their way into the /default folder then you will not be able to delete them using the UI.  Otherwise, check the permissions on the dashboards to make sure you have write access to them.  Failing that, the CLI may be your best answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

probably "rm -f <AXML file>"  is the only option for you? And remember that never try to add search app to Deployer to clean up these!!!

Have you try to look that via "Settings -> All Configurations"? With some objects (e.g. users private) that could help you.

My advise for future is never put any KO inside Search app. You always should use separate app(s) for your own KOs and manage those via Deployer. 

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...