How to backup Splunk dashboards,reports and alerts from default search app before upgrading to the latest Splunk enterprise version?
if the dashboards,alerts and reports are private ( not shared with App OR system) then you will find them
$SPLUNK_HOME/etc/users/<username>/<anyapp>/
for example , if you as admin have created report or alert which is not shared with anyone in search & reporting app then
$SPLUNK_HOME/etc/users/admin/search/local/savedsearches.conf
dashboard which is not shared created in search & reporting application
$SPLUNK_HOME/etc/users/admin/search/local/data/ui/views
for the reports, alerts and dashboard that are shared at least with app or system then
$SPLUNK_HOME/etc/apps/<appname>
for example , if you as admin have created report or alert which is shared with anyone in search & reporting app then
$SPLUNK_HOME/etc/apps/search/local/savedsearches.conf
dashboard which is shared created in search & reporting application
$SPLUNK_HOME/etc/apps/search/local/data/ui/views
@thambisetty can you provide me the exact path where I can find my dashboards,alerts and reports configurations.
All my dashboards,alerts and reports are in search app.
if the dashboards,alerts and reports are private ( not shared with App OR system) then you will find them
$SPLUNK_HOME/etc/users/<username>/<anyapp>/
for example , if you as admin have created report or alert which is not shared with anyone in search & reporting app then
$SPLUNK_HOME/etc/users/admin/search/local/savedsearches.conf
dashboard which is not shared created in search & reporting application
$SPLUNK_HOME/etc/users/admin/search/local/data/ui/views
for the reports, alerts and dashboard that are shared at least with app or system then
$SPLUNK_HOME/etc/apps/<appname>
for example , if you as admin have created report or alert which is shared with anyone in search & reporting app then
$SPLUNK_HOME/etc/apps/search/local/savedsearches.conf
dashboard which is shared created in search & reporting application
$SPLUNK_HOME/etc/apps/search/local/data/ui/views
Hi @sanjubaba,
see in $SPLUNK_HOME/etc/apps/search
Dashboards are in $SPLUNK_HOME/etc/apps/search/local/data/ui/views
Alerts and reports are in savedsearches.conf in $SPLUNK_HOME/etc/apps/search/local
Ciao.
Giuseppe
backup only $SPLUNK_HOME/etc