Deployment Architecture

How do I copy the dashboards from the search app to a new distributed search system?

nls7010
Path Finder

We have created a new Splunk 6.6.3 cluster environment with 3SH and 6 indexers. I've been asked to copy the saved searches, dashboards, etc from the old system to the new system. Unfortunately it seems all of the dashboards were created under the default search application.

How do I move from the \etc\apps\search\local to the new clustered system?

0 Karma

mstjohn_splunk
Splunk Employee
Splunk Employee

Hi @nls7010 - Did any of these answers provide a working solution to your question? If yes, don't forget to click "Accept" to close out your question so that others can easily find it if they are having the same issue. Otherwise, please give us more information so someone else can suggest a fix. Thanks and happy Splunking!

0 Karma

sudosplunk
Motivator

Follow these steps and see if it works for you,

On deployer, create an app with some name "old_stuff_from_search_app" under $SPLUNK_HOME/etc/shcluster/apps/ directory.

Copy local directory from search app on old search head and paste it inside "old_stuff_from_search_app"

Push configurations to search heads -- From deployer, $SPLUNK_HOME/bin, run this command, ./splunk apply shcluster-bundle -target <captain_URI>:8089 -auth <username>:<password>

More info here.

0 Karma

vishaltaneja070
Motivator

If it is search head clustered environment, then the best way to do it is to create it in Captain instance. Copying the configuration files for dashboard is hactic task, just copy the xmls and create new dashboards.
For saved searches, savedsearches.conf file is avaible you can copy that.

Captain will replicate all the search artifacts and saved searches to other SHC members.

0 Karma

nls7010
Path Finder

There are also a number of xml files in the etc/apps/search/local/data/ui/views, how do I copy that over as well?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...