Deployment Architecture

Getting the warning "Splunk has found # orphaned searches owned by # unique disabled users", but no results displayed


We are running Splunk Enterprise v. 7.0.4 on our search head cluster.
Recently we have started to get the following warning:

"Splunk has found 4 orphaned searches owned by 1 unique disabled users.Click to view the orphaned scheduled searches. Reassign them to a valid user to re-enable or alternatively disable the searches."

but the click would take us to a search that won't produce any results.

Strange, that running Health Check on Splunk DMC server doesn't show any scheduled orphaned searches on the same search heads.

Any ideas?

0 Karma


After clicking on the link few times across 4-5 days, I was finally able to see some results. We are running 4 search heads cluster.

0 Karma


Hi @mlevsh,

it's weird that there isn't any result. I also don't have a clue why... maybe permissions.

I'll provide you a link though how you can resolve orphaned knowledge objects. 🙂


@pyro_wood, I'm a Splunk admin, so it should cover permissions.
We had similar warnings before and resolved orphaned searches, but this time it's hard to be sure what user/searches combination is causing the warning to pop up.

0 Karma
Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...