I'm in the process of migrating a single-host Splunk system to a two-host (1 indexer + 1 searchhead) setup.
I already had everything up and running properly, but now suddenly all my reports and dashboards have disappeared from the Web-UI.
I carefully compared the old and the new setup and everything seems to be in place where they should be (in $SPLUNKDIR/etc/apps/*).
So to summarize: I haven't changed anything (no config changes, no restarts) since last week but now suddenly the Dashboards are no longer visible.
Any hint of what to do here?
I figured out the problem. It was a stupid mistake on my side. I have a loadbalancer in front and that actually pointed to the indexer instead of the searchhead. Once I access the searchhead directly everything works as expected.
I figured out the problem. It was a stupid mistake on my side. I have a loadbalancer in front and that actually pointed to the indexer instead of the searchhead. Once I access the searchhead directly everything works as expected.
Hi @ffloimair,
Check if dashboard (etc/apps//default/data/ui/views/) and reports (etc/apps//default/savedsearches.conf) is present or not on search-head.
Yes, they are present
Try restarting splunk search head. It ideally should show in Settings > User Interfaces > Views and Settings > "Select Permission in front of your dashboard".
Did a restart and tried as suggested, but it doesn't show up there either.