How to clone reports from Splunk Ent to ES ( Ent. Security)?
If you have ES on the same search head where the reports are located, You can just use Edit>Move from UI.
If you they are on different search head or you have large number of reports that you want to migrate, You can Copy their definition from savedsearches.conf(From where it is defined now) and paste it in local/savedsearches.conf in ES app.
Thank u for your message. I just found it. Splunk Ent. & ES are not on the same SH. How do I clone it now please. Thank u in advance?
The transfer knowledge object scripts might work for this https://github.com/gjanders/Splunk