Dashboards & Visualizations

Sharing a dashboard on an indexer with a search head

danielpellarini
Path Finder

I have several dashboards and views created on an indexer (this was done before configuring distributed search). I have now set up distributed search and added a search head. Is it possible to see all these dashboards from the search head without having to create them again?

0 Karma
1 Solution

rturk
Builder

Hi Daniel,
There's probably a better way to do this, but:

  1. Give all of the apps, saved searches, lookups, and dashboards you made on the Indexer "App" permissions.
  2. Make a copy of all the apps in $SPLUNK_HOME/etc/apps/ on the Indexer (these will contain all of your backups)
  3. Copy them to the new Search Head (See NOTE)

NOTE: This will overwrite any app configuration of identically named apps on the Search Head, so I'd make a copy of them first.

I hope this helps 🙂

View solution in original post

rturk
Builder

Hi Daniel,
There's probably a better way to do this, but:

  1. Give all of the apps, saved searches, lookups, and dashboards you made on the Indexer "App" permissions.
  2. Make a copy of all the apps in $SPLUNK_HOME/etc/apps/ on the Indexer (these will contain all of your backups)
  3. Copy them to the new Search Head (See NOTE)

NOTE: This will overwrite any app configuration of identically named apps on the Search Head, so I'd make a copy of them first.

I hope this helps 🙂

danielpellarini
Path Finder

Hey thanks for the answer 🙂 I thought about this as well, but isn't there any way though to somehow make the dashboards visible to the search head without any copying and pasting, keeping them on the indexer?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...