Deployment Architecture

Orphaned Searches: how do you disable the orphan notifications on search head members?

koshyk
Super Champion

hi,

We have quite a large amount of users and hence leavers/movers are common. We are aware of how to fix the orphaned searches, but we do it in a reactive way. But if a person leaves, immediately it starts popping up on the search head, which is visible to other users too.

We have a deployer, which has oversight of all search heads, and it is also showing there, which is good enough for administrators.

Hence the query,..which .conf file can we push the configs to search heads only, so the orphaned notifications are NOT shown?

0 Karma
1 Solution

mlevsh
Builder

@koshyk
http://docs.splunk.com/Documentation/Splunk/7.2.0/Knowledge/Resolveorphanedsearches:
"If you would rather not receive these notifications, open limits.conf, look for the [system_checks] stanza, and set orphan_searches to disabled"

Modify the link according to your Splunk version.

View solution in original post

0 Karma

mlevsh
Builder

@koshyk
http://docs.splunk.com/Documentation/Splunk/7.2.0/Knowledge/Resolveorphanedsearches:
"If you would rather not receive these notifications, open limits.conf, look for the [system_checks] stanza, and set orphan_searches to disabled"

Modify the link according to your Splunk version.

0 Karma

koshyk
Super Champion

thank you mate. cheers

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...