Dashboards & Visualizations

Is it possible to copy savedsearches.conf from an old Splunk app to a recent one (newest Splunk version)?

skender27
Contributor

Hi,

The requirement is to have the same dashboard (lots of href links to searches in Splunk organized in blockes) when building up a new Splunk distributed platform.

I am thinking to reuse the same savedsearches.conf (a large one made in html) from a Splunk 5.0.9 to a recent version and so copying it under the same app local folder...
What issues should I consider (except removing the vsid row from each search saved)?

Thanks a lot,
Skender

0 Karma

somesoni2
Revered Legend

You would need to copy the savedsearches.conf and corresponding local.meta entries (yourApp/metadata folder). The local.meta would define the permissions and scope (visibility) for the searches (required).

skender27
Contributor

Unfortunatelly no (should I override the existing folder?).

In fact, it is unnecessary now because some of them are obsolete . Well in this case I think I have to re-create all the searches which feed the href links of the dashboard.

I will let you know,
Skender

0 Karma

skender27
Contributor

Hi,

I tried deleting the vsid attributes from the copied savedsearches.conf, but still i couldn't get the old searches.
Probably because of different Splunk versions: the old one was a Enterprise 5.0.8 and the new one was a 6.4.
Could it be the reason?

Skender

0 Karma

somesoni2
Revered Legend

And did you copy the .meta entries as well?

0 Karma

skender27
Contributor

Sure, I will try next week and I'll share how this behaves.

Thanks a lot,
Skender

0 Karma

skender27
Contributor

Precision: "a large one made in html" I mean the dashboard, not the .conf file.

Skender

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

Yes, Should be perfectly fine. Give it a try and let me know the results.

skender27
Contributor

I can try this only the next week...
I will share all the results about this issue.

Thanks,
Skender

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...