Installation

How to retrieve all apps and reports from the backup after uninstalling and reinstalling Splunk?

pbourit
New Member

Hi

We had to uninstall then reinstall Splunk recently. In order to be sure to not lose all apps and reports, we have to copy the entire Splunk field and we have created a *.spl for each app.

After the reinstallation, we have imported these *.spl and the Apps are created but totally empty! No reports, no search, nothing.

So, we assume we need to copy some files from the backup to the new Splunk folder, but which ones? How to find all of our research?

Thank you

Labels (1)
0 Karma

musskopf
Builder

Inside Splunk, you'll have a folder named etc/apps/. Inside each App's Folder, go to the local/ folder and you should be able to find all configuration files, saved searches, reports, etc there. You might also be interested in the lookups/ folder as well.

0 Karma

musskopf
Builder

If they were all private objects, you might find those inside $SPLUNK_HOME/etc/users/<USERNAME>/<APPNAME>/local

For example, I have a private dashboard at:

/apps/splunk/etc/users/admin/search/local/data/ui/views/dev__printing.xml

Hope that helps.
Cheers

pbourit
New Member

I am really disapointed : all files in the local folder are empty... It seems all my reports, searches etc... are not in the Apps folder (whereas they are all linked to this App). Where it can be ?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...