Dears,
I have around 100 alerts configured in splunk with one AD user.
Since this AD user is left the organization, I need to change the ownership of all alerts under his name to my name.
Is this possible in splunk. I couldn't find any docs as such for this.
Tried looking at savedsearch.conf under the app but there is nothing like owner filed in any alert.
Thanks,
Ramu Chittiprolu
If you are on a new enough version of Splunk, there's now UI pieces that cover this use case exactly. Relevant Docs: http://docs.splunk.com/Documentation/Splunk/7.1.1/Knowledge/Resolveorphanedsearches#Bulk-reassign_mu...
If not, the REST API has a method of updating the ACLs of a knowledge object: https://docs.splunk.com/Documentation/Splunk/7.1.1/RESTUM/RESTusing#Access_Control_List
Otherwise you're looking inside of metadata directories inside of apps and the system dir for default.meta and/or local.meta files and changing those then restarting: http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/defaultmetaconf
If you are on a new enough version of Splunk, there's now UI pieces that cover this use case exactly. Relevant Docs: http://docs.splunk.com/Documentation/Splunk/7.1.1/Knowledge/Resolveorphanedsearches#Bulk-reassign_mu...
If not, the REST API has a method of updating the ACLs of a knowledge object: https://docs.splunk.com/Documentation/Splunk/7.1.1/RESTUM/RESTusing#Access_Control_List
Otherwise you're looking inside of metadata directories inside of apps and the system dir for default.meta and/or local.meta files and changing those then restarting: http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/defaultmetaconf
My splunk version is 6.6.3.
Does the above documentation applicable ?
es, I did it myself, and I am currently running SPLUNK version 8.0.4.
It appears so. Merely change the text 7.1.1
in the URL, or toggle the Version drop down on the top of the page (upper right) to validate for the given version you are using. Enjoy!
Thank you. It worked flawlessly.