Knowledge Management

Configure Data Model Acceleration to run as a particular user?

wryanthomas
Contributor

A data model acceleration is populating summary with "friendly" values from an automatic lookup (replacing a guid-like value) that I built for "privileged" users ... a lookup that I wish to retain (for dashboard purposes). But I can't figure out how to have acceleration summary not include that "friendly" lookup value. This appears to be because 'nobody' is always the one running acceleration searches. I'd like to be able to specify the user running the acceleration query for this data model to prevent the automatic lookup, but I can't see how to specify user of acceleration searches.

All other acceleration config parameters appear to be in datamodels.conf. But I'm not seeing any option to specify alternative  "owner" / "run_as" account.

Is it not possible to specify owner on the acceleration searches? Or is there another path to get acceleration searches to run as a particular user?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...