- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
srunyon
New Member
01-13-2016
08:52 AM
I added several objects to the "Vulnerabilities" data model. After that the Enterprise Security /Security Domains/Network/Vulnerability Center dashboard started showing inconsistent values in some panels and has "search is waiting for input" on other panels. Is there a way to return the data model and the dashboard to the original configuration before I screwed them up?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mdessus_splunk

Splunk Employee
01-13-2016
11:45 AM
On way to do it is to go to your Splunk home directory and delete the custom files:
- /opt/splunk/etc/apps/Splunk_SA_CIM/default/data/models/xxx.json for datamodel
- /opt/splunk/etc/apps/xxx/local/data/ui/views/yyy.xml (or etc/users/ if they are private) for dashboards (you may use the find command if you do not know the apps they are belong too).
And you need to restart Splunk after.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mdessus_splunk

Splunk Employee
01-13-2016
11:45 AM
On way to do it is to go to your Splunk home directory and delete the custom files:
- /opt/splunk/etc/apps/Splunk_SA_CIM/default/data/models/xxx.json for datamodel
- /opt/splunk/etc/apps/xxx/local/data/ui/views/yyy.xml (or etc/users/ if they are private) for dashboards (you may use the find command if you do not know the apps they are belong too).
And you need to restart Splunk after.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
srunyon
New Member
01-13-2016
01:19 PM
Deleting the files and restarting restored the items. Thanks for the help.
