<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Who do saved scheduled searches run as? in Security</title>
    <link>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154871#M4666</link>
    <description>&lt;P&gt;what access does splunk-system-user have? Is it like god access? &lt;/P&gt;</description>
    <pubDate>Wed, 08 Oct 2014 03:56:52 GMT</pubDate>
    <dc:creator>juniormint</dc:creator>
    <dc:date>2014-10-08T03:56:52Z</dc:date>
    <item>
      <title>Who do saved scheduled searches run as?</title>
      <link>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154869#M4664</link>
      <description>&lt;P&gt;I'm trying to figure out how to have a saved search editable by all the people in a role without creating an opportunity for privileged escalation.  This led me to ask questions around who a saved search run's as.  &lt;/P&gt;

&lt;P&gt;How does it work?  Is it the owner?  If yes, what if no owner is specified?   &lt;/P&gt;

&lt;P&gt;I think I would like it to be something like specify a role that it runs as. Is something like that doable?  &lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 18:30:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154869#M4664</guid>
      <dc:creator>juniormint</dc:creator>
      <dc:date>2014-10-07T18:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Who do saved scheduled searches run as?</title>
      <link>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154870#M4665</link>
      <description>&lt;P&gt;The saved searches run as the user who owns it. If no owner is specified  (No owner is shown in UI or nobody in .meta files), it runs as splunk-system-user account. If you want searches to run as a role, you need to create a user (can keep the same name as the role) having that role and change the owner of the search with that role  (by updating owner property in local.meta file).&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 20:58:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154870#M4665</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-10-07T20:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Who do saved scheduled searches run as?</title>
      <link>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154871#M4666</link>
      <description>&lt;P&gt;what access does splunk-system-user have? Is it like god access? &lt;/P&gt;</description>
      <pubDate>Wed, 08 Oct 2014 03:56:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154871#M4666</guid>
      <dc:creator>juniormint</dc:creator>
      <dc:date>2014-10-08T03:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Who do saved scheduled searches run as?</title>
      <link>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154872#M4667</link>
      <description>&lt;P&gt;NEW FEATURE UPDATE!  See documentation here:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.1511/Report/Createandeditreports"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.1511/Report/Createandeditreports&lt;/A&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;5. (Optional) Determine whether the search should run as Owner or run as User.

This setting determines whether the search runs with the permissions of the search Owner (the person who defined the search) or the permissions of the search User (the person who is running the search). Reports run as Owner by default.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For a detailed explanation of why this setting is significant and how it works, see "Running reports as the report owner or report user," in this topic.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.1511/Report/Createandeditreports#Determine_whether_to_run_reports_as_the_report_owner_or_report_user"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.1511/Report/Createandeditreports#Determine_whether_to_run_reports_as_the_report_owner_or_report_user&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2016 16:10:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Who-do-saved-scheduled-searches-run-as/m-p/154872#M4667</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2016-01-13T16:10:27Z</dc:date>
    </item>
  </channel>
</rss>

