Reporting

Is there some way to call saved searches via loadjob WITHOUT specifying the username/owner?

jamesvz84
Communicator

There are some saved searches that are used in our organization and called via "loadjob". The problem is, that the creator/owner of these saved searches will soon be leaving our group and so we are looking to delete his username.

Is there some way to call saved searches via loadjob WITHOUT referencing the username? I can imagine this happening again and us having to once again re-assign the user just to make the searches work. It would be better if the searches just kept working without intervention.

vasanthmss
Motivator

Hi James,

May be whenever you are delivering / after testing, manually you can move all the search to no owner / admin in the local.metadata file. Its one time activity. after changing you can use either admin / nobody based on your configuration.

$Splunk_Home$/etc/apps/<appname>/metadata/local.metadata

So don't worry about the user name, always the loadjob will work. 🙂

Cheers!

V
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...