Alerting

Knowledge Object

whitecat001
Explorer

Hello,

There was a user name that was changed and want to transfer ownership of splunk knowledge Object (Alerts) to her new account name . I will like to achieve this through  the cli and also the user changed her name and will want the new name to be applied to the knowledge object


Pls how will i go about effecting this change.  

Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

You could try this https://github.com/harsmarvania57/splunk-ko-change

But usually it’s easier and faster to do that via GUI. Just use Settings-> All objects -> Change ownership (or something like those, I can’t remember exact names).

If that doesn’t work (there are some cases when this cannot change all KOs), you should use previous script.

r. Ismo

 

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...