Knowledge Management

Cleaning up orphaned searches and reports

brent_weaver
Builder

We migrated search heads and there was content in user directories from users that have since quit, and therefore no username got created. I get a message that there are orphaned searched. Any advice?

Tags (1)
0 Karma

maciep
Champion

If you can't use the re-assign objects interface for those searches, then i would suggest either deleting savedsearches.conf from the user ($SPLUNK_HOME/etc/users/the_user/some_app/local/savedsearches.conf) or just delete the user directory all together. If it's shc, you can do that on each member and then a rolling restart.

Of course, first ensure those searches should no longer be running. If they should still be running, then just recreate them yourself.

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...