Saved Searches not keeping configuration while changing owner by REST as below;
curl -k -u admin:changeme https://SH:8089/servicesNS/"owner name"/"app name"/saved/searches//acl -d owner=newOwner -d sharing=user
After replace some ownership from Alerts I saw those Alerts have lost their scheduled time - they have all "none" in the list. Therefore I tried to open and saving one by one I realised those Alerts had scheduled again.
When I do the same action to the others the REST had lost them again!
It appears all good now after the reload command for saved searches - the changes seems not recognized by the Splunk until it gets reloaded. Make sure to run below after changes to the scheduled searches as best practice.
./splunk _internal call /servicesNS/newOwner/AppName/saved/searches/_reload
It appears all good now after the reload command for saved searches - the changes seems not recognized by the Splunk until it gets reloaded. Make sure to run below after changes to the scheduled searches as best practice.
./splunk _internal call /servicesNS/newOwner/AppName/saved/searches/_reload
You should click Accept
on your answer to close the question.