Splunk Enterprise

What is "default.old.<date>" and can it be removed

fatsug
Builder

Hello community

After a small "snafu" with new dashboards and version number, I noticed that after the rollout in our distributed environment there was, what seemed like, a local backup present:

    /opt/splunk/etc/apps/<appname>/default.old.20220705-235555/

The date lines up with the rollout of dashboards receiving a "This dashboard view is deprecated and will be removed in future versions of Splunk software" error.  Hence, I suspect these are connected in some way.

So the dashboards were "repaired" by just dropping the version number by "1", though the "backup files" are still there.

The only difference I notice are the install_source_checksum and the changes made to dashboards.

So, is it OK to just delete this "backup" folder? If so, is there a preferred way to do so or just remove it?

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

I believe it is safe to remove the "default.old" folders.  There's no Splunk way to do it so just use rm -r.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

I believe it is safe to remove the "default.old" folders.  There's no Splunk way to do it so just use rm -r.

---
If this reply helps you, Karma would be appreciated.

fatsug
Builder

I've been watching the folder and it has not been accessed once, neither is there a single difference except for the later modification. Hence, removing it seemed safe enough and I have not observed any issues.

Thx

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...