Splunk Search

## Where do you manually delete certain reports or dashboards on the server?

Builder

So I have mass copied the search app from Server A to Server B (Along with the users directory) to basically copy over all the reports and dashboards.. however now I'd like to delete about 100 reports from Server B. Can someone help me identify the appropriate files to delete while on the server within the directories (C:\program files\splunk\etc......). Say I had a report called: Test, what files do I need to delete from within the server to accomplish this?

Tags (4)
1 Solution
Revered Legend

To delete dashboard, you need to delete corresponding .xml files from following locations:

``````C:\program files\splunk\etc\apps\search\local\data\ui\views  (for dashboards shared in app/global)
-You would also need to remove local.meta entry (not the whole file just the corresponding entry from C:\program files\splunk\etc\apps\search\metadata\local.meta file

``````

For reports, you need to delete corresponding entries in the savedsearches.conf files (not the whole file just the corresponding entries) from following locations:

``````C:\program files\splunk\etc\apps\search\local\savedsearches.conf  (for reports shared in app/global)
-You would also need to remove local.meta entry (not the whole file just the corresponding entry from C:\program files\splunk\etc\apps\search\metadata\local.meta file

``````
Revered Legend

To delete dashboard, you need to delete corresponding .xml files from following locations:

``````C:\program files\splunk\etc\apps\search\local\data\ui\views  (for dashboards shared in app/global)
-You would also need to remove local.meta entry (not the whole file just the corresponding entry from C:\program files\splunk\etc\apps\search\metadata\local.meta file

``````

For reports, you need to delete corresponding entries in the savedsearches.conf files (not the whole file just the corresponding entries) from following locations:

``````C:\program files\splunk\etc\apps\search\local\savedsearches.conf  (for reports shared in app/global)
-You would also need to remove local.meta entry (not the whole file just the corresponding entry from C:\program files\splunk\etc\apps\search\metadata\local.meta file