Deployment Architecture

Orphaned Searches: how do you disable the orphan notifications on search head members?

koshyk
Super Champion

hi,

We have quite a large amount of users and hence leavers/movers are common. We are aware of how to fix the orphaned searches, but we do it in a reactive way. But if a person leaves, immediately it starts popping up on the search head, which is visible to other users too.

We have a deployer, which has oversight of all search heads, and it is also showing there, which is good enough for administrators.

Hence the query,..which .conf file can we push the configs to search heads only, so the orphaned notifications are NOT shown?

0 Karma
1 Solution

mlevsh
Builder

@koshyk
http://docs.splunk.com/Documentation/Splunk/7.2.0/Knowledge/Resolveorphanedsearches:
"If you would rather not receive these notifications, open limits.conf, look for the [system_checks] stanza, and set orphan_searches to disabled"

Modify the link according to your Splunk version.

View solution in original post

0 Karma

mlevsh
Builder

@koshyk
http://docs.splunk.com/Documentation/Splunk/7.2.0/Knowledge/Resolveorphanedsearches:
"If you would rather not receive these notifications, open limits.conf, look for the [system_checks] stanza, and set orphan_searches to disabled"

Modify the link according to your Splunk version.

0 Karma

koshyk
Super Champion

thank you mate. cheers

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...