<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to delete or disable the orphaned searches in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627396#M218017</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252469"&gt;@Harish2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, private scheduled searches can be a pain to share/disable.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I assume you are a Splunk admin on your platform.&amp;nbsp; You could try and find the saved search under &lt;EM&gt;Settings &amp;gt; Searches, reports, and alerts.&amp;nbsp;&lt;/EM&gt; This sometimes works.&lt;/P&gt;&lt;P&gt;If it does show there then a Splunk admin should be able to disable or share the saved search.&amp;nbsp; Once shared you should also be able to reassign ownership under Reassign Knowledge objects.&lt;BR /&gt;&lt;BR /&gt;In my environment, authentication is LDAP based.&amp;nbsp; When a user is removed (no longer appears under Settings &amp;gt; Users) we sometimes have to create a temp local user, with the exact same username, log on as that user and then disable/share their private saved search.&amp;nbsp; Once done the temp local user can be deleted again.&lt;BR /&gt;&lt;BR /&gt;Hope this helps&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jan 2023 22:36:55 GMT</pubDate>
    <dc:creator>yeahnah</dc:creator>
    <dc:date>2023-01-17T22:36:55Z</dc:date>
    <item>
      <title>How to delete or disable the orphaned searches?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627394#M218016</link>
      <description>&lt;P&gt;i have few orphaned searches, which i need to reassign or disable or delete it. i am not able to do any of these.&lt;BR /&gt;&lt;BR /&gt;1. The orphaned searches which can see in&amp;nbsp; splunk/app/search/orphaned_scheduled_searches..............&lt;BR /&gt;here the sharing is in user level.&lt;BR /&gt;but i am not able to see the same&amp;nbsp; in&amp;nbsp; settings&amp;gt;All configurations&amp;gt;Reassign Knowledge objects.&lt;BR /&gt;when i search the alert name by selecting the orphaned i am not getting any results.&lt;BR /&gt;&lt;BR /&gt;2. When i checked the owner name in internal index it is showing that user has been disabled.&lt;BR /&gt;&lt;BR /&gt;Now how can i&amp;nbsp;reassign or disable or delete this searches.&lt;BR /&gt;is there any chance to do via CLI.&lt;BR /&gt;please help on this.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 17:57:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627394#M218016</guid>
      <dc:creator>Harish2</dc:creator>
      <dc:date>2023-01-18T17:57:04Z</dc:date>
    </item>
    <item>
      <title>Re: how to delete or disable the orphaned searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627396#M218017</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252469"&gt;@Harish2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, private scheduled searches can be a pain to share/disable.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I assume you are a Splunk admin on your platform.&amp;nbsp; You could try and find the saved search under &lt;EM&gt;Settings &amp;gt; Searches, reports, and alerts.&amp;nbsp;&lt;/EM&gt; This sometimes works.&lt;/P&gt;&lt;P&gt;If it does show there then a Splunk admin should be able to disable or share the saved search.&amp;nbsp; Once shared you should also be able to reassign ownership under Reassign Knowledge objects.&lt;BR /&gt;&lt;BR /&gt;In my environment, authentication is LDAP based.&amp;nbsp; When a user is removed (no longer appears under Settings &amp;gt; Users) we sometimes have to create a temp local user, with the exact same username, log on as that user and then disable/share their private saved search.&amp;nbsp; Once done the temp local user can be deleted again.&lt;BR /&gt;&lt;BR /&gt;Hope this helps&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 22:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627396#M218017</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-01-17T22:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: how to delete or disable the orphaned searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627400#M218020</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158935"&gt;@yeahnah&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;If it does show there then a Splunk admin should be able to disable or share the saved search.&amp;nbsp; Once shared you should also be able to reassign ownership under Reassign Knowledge objects.---&amp;gt; here also i am not able to see the orphaned&amp;nbsp; alerts&amp;nbsp; to disable or reassign&lt;BR /&gt;&lt;BR /&gt;In my environment, authentication is LDAP based.&amp;nbsp; When a user is removed (no longer appears under Settings &amp;gt; Users) we sometimes have to create a temp local user, with the exact same username, log on as that user and then disable/share their private saved search.&amp;nbsp; Once done the temp local user can be deleted again.---&amp;gt; yes i am an admin, but i am not sure how to create this user and delete again&lt;BR /&gt;&lt;/SPAN&gt;can you please provide complete steps to do this activity.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 23:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627400#M218020</guid>
      <dc:creator>Harish2</dc:creator>
      <dc:date>2023-01-17T23:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: how to delete or disable the orphaned searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627401#M218021</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252469"&gt;@Harish2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's simple enough via the UI - try on a test system to become familiar.&lt;BR /&gt;&lt;BR /&gt;Depending on the version of Splunk you have, the add new user steps may be slightly different.&amp;nbsp; The best place to to look is via the excellent Splunk documentation.&amp;nbsp; Here's a link to the latest version (assuming Splunk Enterprise).&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Security/Addandeditusers" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.3/Security/Addandeditusers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Select the relevant Splunk version (UI: Help &amp;gt; About) at the top of the doc and give it a go.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Note: You may need to look at an existing user to see what Splunk roles the new user needs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 23:51:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627401#M218021</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-01-17T23:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: how to delete or disable the orphaned searches</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627646#M218087</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158935"&gt;@yeahnah&lt;/a&gt;&amp;nbsp;, Thanks for your help, it really worked.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 20:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-delete-or-disable-the-orphaned-searches/m-p/627646#M218087</guid>
      <dc:creator>Harish2</dc:creator>
      <dc:date>2023-01-19T20:28:22Z</dc:date>
    </item>
  </channel>
</rss>

