Splunk Enterprise

What is "default.old.<date>" and can it be removed

fatsug
Contributor

Hello community

After a small "snafu" with new dashboards and version number, I noticed that after the rollout in our distributed environment there was, what seemed like, a local backup present:

    /opt/splunk/etc/apps/<appname>/default.old.20220705-235555/

The date lines up with the rollout of dashboards receiving a "This dashboard view is deprecated and will be removed in future versions of Splunk software" error.  Hence, I suspect these are connected in some way.

So the dashboards were "repaired" by just dropping the version number by "1", though the "backup files" are still there.

The only difference I notice are the install_source_checksum and the changes made to dashboards.

So, is it OK to just delete this "backup" folder? If so, is there a preferred way to do so or just remove it?

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I believe it is safe to remove the "default.old" folders.  There's no Splunk way to do it so just use rm -r.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I believe it is safe to remove the "default.old" folders.  There's no Splunk way to do it so just use rm -r.

---
If this reply helps you, Karma would be appreciated.

fatsug
Contributor

I've been watching the folder and it has not been accessed once, neither is there a single difference except for the later modification. Hence, removing it seemed safe enough and I have not observed any issues.

Thx

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...