Getting Data In

Creating service account in splunk to re-assign the orphaned knowledge object

man03359
Communicator

Hi,

I am a splunk admin and we are re-assigning the orphaned knowledge object to my name as a temporary solution. I need to create a service account so that I can assign the orphaned knowledge objects to that account. I am doing it for the first time. Could some one please  specify what roles and capacities I should assign. Also is it the same process to create a service account same as how we create a local user in splunk like Settings > Users > Create User

 

ps. I am on splunk cloud | version: 9.3

Labels (1)
0 Karma
1 Solution

livehybrid
SplunkTrust
SplunkTrust

Hi

Yes, creating a service account in Splunk Cloud is the same as creating a local user via Settings > Users > Create User.

  • Roles: Assign the minimum privileged role for the service account own and manage the required knowledge objects, run searches etc. Optionally, create a custom role dedicated for the service user.
  • App context: Ensure the role has write permissions on relevant apps where knowledge objects reside.

This service account will then be a stable owner for orphaned knowledge objects, avoiding future orphaning if admins or users who own the KOs were to leave.

  • Use a strong, unique password and store it securely.
  • Document the account purpose and ownership internally.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

View solution in original post

livehybrid
SplunkTrust
SplunkTrust

Hi

Yes, creating a service account in Splunk Cloud is the same as creating a local user via Settings > Users > Create User.

  • Roles: Assign the minimum privileged role for the service account own and manage the required knowledge objects, run searches etc. Optionally, create a custom role dedicated for the service user.
  • App context: Ensure the role has write permissions on relevant apps where knowledge objects reside.

This service account will then be a stable owner for orphaned knowledge objects, avoiding future orphaning if admins or users who own the KOs were to leave.

  • Use a strong, unique password and store it securely.
  • Document the account purpose and ownership internally.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...