Deployment Architecture

Getting the warning "Splunk has found # orphaned searches owned by # unique disabled users", but no results displayed

mlevsh
Builder

We are running Splunk Enterprise v. 7.0.4 on our search head cluster.
Recently we have started to get the following warning:

"Splunk has found 4 orphaned searches owned by 1 unique disabled users.Click to view the orphaned scheduled searches. Reassign them to a valid user to re-enable or alternatively disable the searches."

but the click would take us to a search that won't produce any results.

Strange, that running Health Check on Splunk DMC server doesn't show any scheduled orphaned searches on the same search heads.

Any ideas?

0 Karma

mlevsh
Builder

After clicking on the link few times across 4-5 days, I was finally able to see some results. We are running 4 search heads cluster.

0 Karma

horsefez
Motivator

Hi @mlevsh,

it's weird that there isn't any result. I also don't have a clue why... maybe permissions.

I'll provide you a link though how you can resolve orphaned knowledge objects. 🙂

http://docs.splunk.com/Documentation/Splunk/7.1.2/Knowledge/Resolveorphanedsearches

mlevsh
Builder

@pyro_wood, I'm a Splunk admin, so it should cover permissions.
We had similar warnings before and resolved orphaned searches, but this time it's hard to be sure what user/searches combination is causing the warning to pop up.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...