Building for the Splunk Platform

Is there any effects, if ownership of savedsearches is "nobody"?


I believe that if ownership is nobody, it runs as role splunk-system-user, and splunk-system-user Inherits role admin, so it runs as admin.

Of course, if savedsearches contain knowledge objects(*macro, eventtype, lookup table etc...) that are private permittion of other user, it will be fail.

But in other cases, is my understanding that there is no particular influence is correct?

0 Karma



I can´t find it anymore, but I once read that searches running as nobody will have a lower priority for the scheduler.

But since nobody is often applied as user for e.g. apps, when they get installed, I don´t see any reason to change this. Never had any bad experience with user nobody.

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...