Reporting

Dashboards,Alerts,Reports backup

sanjubaba
Path Finder

How to backup Splunk dashboards,reports and alerts from default search app before upgrading to the latest Splunk enterprise version?

0 Karma
1 Solution

thambisetty
Super Champion

@sanjubaba 

if the dashboards,alerts and reports are private ( not shared with App OR system) then you will find them
$SPLUNK_HOME/etc/users/<username>/<anyapp>/

for example , if you as admin have created report or alert which is not shared with anyone in search & reporting app then

 $SPLUNK_HOME/etc/users/admin/search/local/savedsearches.conf

dashboard which is not shared created in search & reporting application

$SPLUNK_HOME/etc/users/admin/search/local/data/ui/views

for the reports, alerts and dashboard that are shared at least with app or system then

$SPLUNK_HOME/etc/apps/<appname>

for example , if you as admin have created report or alert which is shared with anyone in search & reporting app then

 $SPLUNK_HOME/etc/apps/search/local/savedsearches.conf

dashboard which is shared created in search & reporting application

$SPLUNK_HOME/etc/apps/search/local/data/ui/views

————————————
If this helps, give a like below.

View solution in original post

Tags (1)

sanjubaba
Path Finder

@thambisetty can you provide me the exact path where I can find my dashboards,alerts and reports configurations.

All my dashboards,alerts and reports are in search app.

0 Karma

thambisetty
Super Champion

@sanjubaba 

if the dashboards,alerts and reports are private ( not shared with App OR system) then you will find them
$SPLUNK_HOME/etc/users/<username>/<anyapp>/

for example , if you as admin have created report or alert which is not shared with anyone in search & reporting app then

 $SPLUNK_HOME/etc/users/admin/search/local/savedsearches.conf

dashboard which is not shared created in search & reporting application

$SPLUNK_HOME/etc/users/admin/search/local/data/ui/views

for the reports, alerts and dashboard that are shared at least with app or system then

$SPLUNK_HOME/etc/apps/<appname>

for example , if you as admin have created report or alert which is shared with anyone in search & reporting app then

 $SPLUNK_HOME/etc/apps/search/local/savedsearches.conf

dashboard which is shared created in search & reporting application

$SPLUNK_HOME/etc/apps/search/local/data/ui/views

————————————
If this helps, give a like below.

View solution in original post

Tags (1)

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

see in $SPLUNK_HOME/etc/apps/search

Dashboards are in $SPLUNK_HOME/etc/apps/search/local/data/ui/views

Alerts and reports are in savedsearches.conf in $SPLUNK_HOME/etc/apps/search/local

Ciao.

Giuseppe

thambisetty
Super Champion

backup only $SPLUNK_HOME/etc

————————————
If this helps, give a like below.
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.