Alerting

Knowledge Object

whitecat001
Explorer

Hello,

There was a user name that was changed and want to transfer ownership of splunk knowledge Object (Alerts) to her new account name . I will like to achieve this through  the cli and also the user changed her name and will want the new name to be applied to the knowledge object


Pls how will i go about effecting this change.  

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You could try this https://github.com/harsmarvania57/splunk-ko-change

But usually it’s easier and faster to do that via GUI. Just use Settings-> All objects -> Change ownership (or something like those, I can’t remember exact names).

If that doesn’t work (there are some cases when this cannot change all KOs), you should use previous script.

r. Ismo

 

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...