Hi there,
I ran a Health Check from the Splunk Master Server and noticed that there were 240 orphaned knowledge objects on the Search Head Cluster Deployment Server. However when logging in to the GUI of this server I saw 513 orphaned knowledge objects.
As far as I understood the objects are being detected as orphaned if the user account is not Enabled. The false positive detections are all associated with enabled user accounts.
Do you have any suggestions how I can troubleshoot that issue?
Thanks,
O
hi @O815163 , just wanted to confirm - if those active users are able to login to Splunk? Are they assigned a custom role or Splunk role? Also, are these searches showing as disabled or enabled? Are they running?