Getting Data In

How do I change the owner of alerts in splunk web UI or conf file?

rchittip
Path Finder

Dears,
I have around 100 alerts configured in splunk with one AD user.
Since this AD user is left the organization, I need to change the ownership of all alerts under his name to my name.

Is this possible in splunk. I couldn't find any docs as such for this.
Tried looking at savedsearch.conf under the app but there is nothing like owner filed in any alert.

Thanks,
Ramu Chittiprolu

Tags (1)
1 Solution

acharlieh
Influencer

If you are on a new enough version of Splunk, there's now UI pieces that cover this use case exactly. Relevant Docs: http://docs.splunk.com/Documentation/Splunk/7.1.1/Knowledge/Resolveorphanedsearches#Bulk-reassign_mu...

If not, the REST API has a method of updating the ACLs of a knowledge object: https://docs.splunk.com/Documentation/Splunk/7.1.1/RESTUM/RESTusing#Access_Control_List

Otherwise you're looking inside of metadata directories inside of apps and the system dir for default.meta and/or local.meta files and changing those then restarting: http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/defaultmetaconf

View solution in original post

acharlieh
Influencer

If you are on a new enough version of Splunk, there's now UI pieces that cover this use case exactly. Relevant Docs: http://docs.splunk.com/Documentation/Splunk/7.1.1/Knowledge/Resolveorphanedsearches#Bulk-reassign_mu...

If not, the REST API has a method of updating the ACLs of a knowledge object: https://docs.splunk.com/Documentation/Splunk/7.1.1/RESTUM/RESTusing#Access_Control_List

Otherwise you're looking inside of metadata directories inside of apps and the system dir for default.meta and/or local.meta files and changing those then restarting: http://docs.splunk.com/Documentation/Splunk/7.1.1/Admin/defaultmetaconf

rchittip
Path Finder

My splunk version is 6.6.3.

Does the above documentation applicable ?

0 Karma

Amirahussein
Path Finder

es, I did it myself, and I am currently running SPLUNK version 8.0.4.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

It appears so. Merely change the text 7.1.1 in the URL, or toggle the Version drop down on the top of the page (upper right) to validate for the given version you are using. Enjoy!

0 Karma

rchittip
Path Finder

Thank you. It worked flawlessly.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Enhance Security Operations with Automated Threat Analysis in the Splunk EcosystemAre you leveraging ...

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...