Change Ownership of alert/searches/dashboard if someone don't have rights to splunk home directory


I was looking for option where i can change ownership of alerts/searches/dashboards from application if i have admin/power rights.

in my organization, we don't have splunk home directory rights as that is deployed on different server but we have admin rights.

is there any other way except change owner in $SPLUNK_HOME/etc/apps//metadata/local.meta file? if not then is it possible that this feature can come in Splunk future version?


0 Karma

Esteemed Legend
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...