Why is the SA-nix app hidden, yet all its saved searches are made global to Splunk? Now all my apps on my search head/indexer show all these searches.
I dont want to break the Splunk App for Unix/Linux but I cant have the searches visible to all users.
This is by design. The unix app uses a TA and SA for knowledge objects.
If you don't want users to be able to see the searches in the SA, change the permissions on the SA, but of course the users won't be able to access the unix app either, so you should make sure they don't have permission to that app either.
The app depends on the presence of the SA and TA because those add-ons contain important search-time knowledge such as event types, macros, field extractions, and saved searches.
Is that because these searches are used in the TA and App too?