Reporting

How to delete an Orphaned Scheduled Searches in Cluster Environment

harshal_chakran
Builder

Hi,
I am planning to delete the orphan scheduled search in Splunk Clustered Search Head.

is there any best way to remove it from one Search Head member to see changes in all member.
Probably a Rest API good for this option, however I am not able to find one.

Can anybody guide me for this.

Thanks in advance.

0 Karma

BainM
Communicator

Hi-
I've seen this happen in our cluster master. The best option/way to do this is to go to (on any clustered SH) Settings -> All Configurations -> Reassign Knowledge Objects button.
Change the 'Object Type:All' to 'savedsearches'
Then click the 'Orphaned' button, wait for it to refresh and then you can bulk re-assign or delete any orphaned saved searches.

Warning! Use this tool with care.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...