<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: assign lookup to other owner in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524179#M3760</link>
    <description>&lt;P&gt;well.. i'm looking at the local.meta and all i see are stanzas like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[server/general]
version = 7.2.6
modtime =&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;nothing with ownership or something similar...&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Oct 2020 07:04:15 GMT</pubDate>
    <dc:creator>sarit_s</dc:creator>
    <dc:date>2020-10-12T07:04:15Z</dc:date>
    <item>
      <title>assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524060#M3736</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Today my lookup files are owned by "nobody", in order to change their permissions i have to assign then to other user such as admin (all the lookups located under system and not under specific app)&lt;/P&gt;&lt;P&gt;since we are working with Kubernetece, we are duplicating our environments and all the changes has to be on the configuration files and not via the web&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;where this file is located ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;sarit&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 10:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524060#M3736</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-10-11T10:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524063#M3738</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149978"&gt;@sarit_s&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;You can find all lookup files at&lt;BR /&gt;Splunk GUI, --&amp;gt;Settings---&amp;gt;Lookups---&amp;gt;Lookup table files&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;EDIT - this above step will list all the lookup files, you can change their permissions, move them to new app, etc.&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;the apps/addons like CIM will have lot of lookup files which are "no owner" and they will work just fine, there will be no issue.&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;to change the ownership of a lookup file, i think you need to update the metadata files.. pls check these:&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-do-you-change-ownership-of-a-lookup-file/m-p/383479" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-do-you-change-ownership-of-a-lookup-file/m-p/383479&lt;/A&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;A href="https://community.splunk.com/t5/Security/Change-App-and-Object-Ownership/td-p/34667" target="_blank"&gt;https://community.splunk.com/t5/Security/Change-App-and-Object-Ownership/td-p/34667&lt;/A&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/change-how-outputlookup-assigns-permissions-and-ownership-to-new/m-p/505573" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/change-how-outputlookup-assigns-permissions-and-ownership-to-new/m-p/505573&lt;/A&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Can-we-create-lookup-table-for-specific-owner/m-p/335771" target="_blank"&gt;https://community.splunk.com/t5/Splunk-Search/Can-we-create-lookup-table-for-specific-owner/m-p/335771&lt;/A&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 12:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524063#M3738</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-11T12:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524064#M3739</link>
      <description>&lt;P&gt;From the GUI i know&lt;/P&gt;&lt;P&gt;but im talking about lookup definition and im wondering if there is a configuration file&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 12:00:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524064#M3739</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-10-11T12:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524065#M3740</link>
      <description>&lt;P&gt;&lt;SPAN&gt;As per Richgalloway's answer from the above links:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You'll have to move the files manually from&amp;nbsp;$SPLUNK_HOME/etc/users/&amp;lt;olduser&amp;gt;/&amp;lt;app&amp;gt;/lookups/*&amp;nbsp;to&amp;nbsp;$SPLUNK_HOME/etc/users/&amp;lt;newuser&amp;gt;/lookups.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the metadata file path:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$SPLUNK_HOME/etc/apps/{AppsDir}/metadata/local.meta&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if an answer helped you, you can add a karma point.. if an answer solved your issue, pls accept it as Solution, so that the question will be moved from unanswered to solved.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 12:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524065#M3740</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-11T12:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524068#M3742</link>
      <description>&lt;P&gt;Since the files are owned by nobody, i cant see them under user folder&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all this information located on some conf file ?&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 12:16:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524068#M3742</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-10-11T12:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524070#M3744</link>
      <description>&lt;P&gt;from /opt/splunk/etc (&lt;SPAN&gt;$SPLUNK_HOME/etc&lt;/SPAN&gt;), you can simply run find command with the filename.csv&lt;/P&gt;&lt;P&gt;linux find command for your reference:&lt;/P&gt;&lt;P&gt;find /opt/splunk/etc -name testlookup.csv -print -exec ls -l {} \;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 12:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524070#M3744</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-11T12:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524071#M3745</link>
      <description>&lt;P&gt;Sorry maybe I didn’t explain my self very well&lt;/P&gt;&lt;P&gt;it is lookup definition. It can be a kvstore or csv file&lt;/P&gt;&lt;P&gt;im looking for a conf file that owned all the configuration and i can change it there&lt;/P&gt;&lt;P&gt;since im using kubernetece i have to make the changes in conf file and deploy it&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 12:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524071#M3745</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-10-11T12:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524073#M3747</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149978"&gt;@sarit_s&lt;/a&gt;&amp;nbsp;..&lt;/P&gt;&lt;P&gt;This page will be helpful to you:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.6/Knowledge/ConfigureCSVlookups" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.6/Knowledge/ConfigureCSVlookups&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note,&amp;nbsp;&lt;SPAN&gt;Lookup tables are created and modified on a&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A title="Splexicon:Searchhead" href="https://docs.splunk.com/Splexicon:Searchhead" target="_blank" rel="noopener noreferrer"&gt;search head&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 12:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524073#M3747</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-11T12:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524076#M3750</link>
      <description>&lt;P&gt;sorry but this is not what im looking for..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i know how to do it by using the gui.. since im working with Kubernetece and every change in the system has to be deployed as system version, i need to make the changes in the conf files themselves.&lt;/P&gt;&lt;P&gt;i know that every gui configuration in splunk has conf file behind it so im looking for this file &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Oct 2020 13:24:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524076#M3750</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-10-11T13:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524134#M3756</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149978"&gt;@sarit_s&lt;/a&gt;&amp;nbsp;.. Please let us know, by&amp;nbsp;&lt;SPAN&gt;Kubernetece, are you creating which Splunk instance(search head/indexer/UF, etc). if you update us more clear information, it will be helpful. thanks.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;karma points are appreciated, if the issue resolved, please accept the reply as solution. thanks.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 02:35:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524134#M3756</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2020-10-12T02:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524159#M3759</link>
      <description>As those are owned by nobody that is usually defined in local.meta or default.meta on same directory hierarchy where those lookups are. In you cases those should be under .../etc/system/lookups and metadata is .../etc/system/metadata. Just add/change needed information on those *.meta files to change the ownership to admin. You can see examples e.g. from .../etc/apps/search/... where those geo* lookups have defined.&lt;BR /&gt;&lt;BR /&gt;Anyhow it's much better to create own app for these and manage those permissions etc under it.&lt;BR /&gt;&lt;BR /&gt;r. Ismo</description>
      <pubDate>Mon, 12 Oct 2020 05:51:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524159#M3759</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-12T05:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524179#M3760</link>
      <description>&lt;P&gt;well.. i'm looking at the local.meta and all i see are stanzas like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[server/general]
version = 7.2.6
modtime =&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;nothing with ownership or something similar...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 07:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524179#M3760</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-10-12T07:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524180#M3761</link>
      <description>&lt;P&gt;all splunk environment created with Kubernetece&amp;nbsp;&lt;BR /&gt;most of the configuration changes are in the search head but i think it doesnt matter which kind of server it is i just need to know which file to update&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 07:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524180#M3761</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2020-10-12T07:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: assign lookup to other owner</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524188#M3762</link>
      <description>You should add owner = &amp;lt;user&amp;gt; there.</description>
      <pubDate>Mon, 12 Oct 2020 08:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/assign-lookup-to-other-owner/m-p/524188#M3762</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-12T08:14:36Z</dc:date>
    </item>
  </channel>
</rss>

