Knowledge Management

Health Check - Orphaned Objects False Positive Detection

O815163
Loves-to-Learn Lots

Hi there,

I ran a Health Check from the Splunk Master Server and noticed that there were 240 orphaned knowledge objects on the Search Head Cluster Deployment Server. However when logging in to the GUI of this server I saw 513 orphaned knowledge objects.

As far as I understood the objects are being detected as orphaned if the user account is not Enabled. The false positive detections are all associated with enabled user accounts.

Do you have any suggestions how I can troubleshoot that issue?

Thanks,
O

0 Karma

Nisha18789
Builder

hi @O815163 , just wanted to confirm - if those active users are able to login to Splunk? Are they assigned a custom role or Splunk role? Also, are these searches showing as disabled or enabled? Are they running?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...