Reporting

Dashboards,Alerts,Reports backup

sanjubaba
Path Finder

How to backup Splunk dashboards,reports and alerts from default search app before upgrading to the latest Splunk enterprise version?

0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

@sanjubaba 

if the dashboards,alerts and reports are private ( not shared with App OR system) then you will find them
$SPLUNK_HOME/etc/users/<username>/<anyapp>/

for example , if you as admin have created report or alert which is not shared with anyone in search & reporting app then

 $SPLUNK_HOME/etc/users/admin/search/local/savedsearches.conf

dashboard which is not shared created in search & reporting application

$SPLUNK_HOME/etc/users/admin/search/local/data/ui/views

for the reports, alerts and dashboard that are shared at least with app or system then

$SPLUNK_HOME/etc/apps/<appname>

for example , if you as admin have created report or alert which is shared with anyone in search & reporting app then

 $SPLUNK_HOME/etc/apps/search/local/savedsearches.conf

dashboard which is shared created in search & reporting application

$SPLUNK_HOME/etc/apps/search/local/data/ui/views

————————————
If this helps, give a like below.

View solution in original post

Tags (1)

sanjubaba
Path Finder

@thambisetty can you provide me the exact path where I can find my dashboards,alerts and reports configurations.

All my dashboards,alerts and reports are in search app.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@sanjubaba 

if the dashboards,alerts and reports are private ( not shared with App OR system) then you will find them
$SPLUNK_HOME/etc/users/<username>/<anyapp>/

for example , if you as admin have created report or alert which is not shared with anyone in search & reporting app then

 $SPLUNK_HOME/etc/users/admin/search/local/savedsearches.conf

dashboard which is not shared created in search & reporting application

$SPLUNK_HOME/etc/users/admin/search/local/data/ui/views

for the reports, alerts and dashboard that are shared at least with app or system then

$SPLUNK_HOME/etc/apps/<appname>

for example , if you as admin have created report or alert which is shared with anyone in search & reporting app then

 $SPLUNK_HOME/etc/apps/search/local/savedsearches.conf

dashboard which is shared created in search & reporting application

$SPLUNK_HOME/etc/apps/search/local/data/ui/views

————————————
If this helps, give a like below.
Tags (1)

gcusello
SplunkTrust
SplunkTrust

Hi @sanjubaba,

see in $SPLUNK_HOME/etc/apps/search

Dashboards are in $SPLUNK_HOME/etc/apps/search/local/data/ui/views

Alerts and reports are in savedsearches.conf in $SPLUNK_HOME/etc/apps/search/local

Ciao.

Giuseppe

thambisetty
SplunkTrust
SplunkTrust

backup only $SPLUNK_HOME/etc

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...