How do i clone a dashboard and lookuptables from one App to another in Splunk
Assuming you don't have suitable admin permissions to directly manipulate knowledge objects, then the simplest way is to
Dashboard
If you cannot edit the dashboard, but can clone it, then clone it privately, edit the dashboard and copy as above
Lookup - assuming the existing lookup is app visible only and NOT global
| inputlookup lookup_to_be_copied.csv
| outputlookup my_tmp_copy.csv
then in the new app space do
| inputlookup my_tmp_copy.csv
| outputlookup new_name_in_new_app.csv
This assumes that when you do the outputlookup, it will get private or global app permissions. If it gets global, then the new app will see this, but take care - you don't want 2 lookups of the same name with global scope.
If it is output as private then you should be able to 'upgrade' the permissions to app scope in the new app.
Much will depend on the permissions you have