Installation

After Splunk upgrade from 5.0.8 to 6.1.4 savedsearches are not showing up.

usha_nittala
New Member

Hi Splunk experts,

I have upgraded the version from 5.0.8 to 6.1.4, but after the upgrade, none of the previously created dashboard is working.

When I check any dashboard this error comes in all the panels.

"Warning: saved search not found: "Avg Response time for each transaction"

and this comes for all my savedsearches.

Can anyone help me figure out what is missing is it permission issue or something else, because info is present in savedsearches.conf

Thanks,
Usha

Labels (1)
0 Karma

Raghav2384
Motivator

Did you do a backup of all your *.confs before the upgrade? Saved seaches should be under savedsearches.conf file
Under /local or app/local etc.
Hope you find em all

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...