Reporting

What is the purpose of setting scheduled search to "RUN AS USER"?

the_wolverine
Champion

Looking for clarification. I have users without scheduling capability who ask me to schedule their saved search. I can go through the motions and set these (as the admin user), save my changes, however the scheduled search actually never runs because the user doesn't have the capability to schedule.

What is the point of allowing me to configure these settings if the user doesn't have the capability?

And what does setting Run as "owner" vs "user" do? My original guess was that the search can be scheduled to run as the user who was scheduling it (me) but clearly that would be too convenient....

renjith_nair
Legend

We also had the same requirement and same issue. From the documents it's just about restricting the permissions on the data and object permissions (Reference : http://docs.splunk.com/Documentation/Splunk/6.3.1511/Report/Createandeditreports#Determine_whether_t...)

Determine whether to run reports as the report owner or report user

When you share a report with other users, you have the option of having it run as the report owner (the person who created the report) or the report "user" (the person who is running the report). This setting is used for two reasons:

    It can allow access to search data that might otherwise be unavailable to the person running the report.
    It helps prevent situations where your concurrent search limit is being hit when too many people run reports that you own. 

Searches run as owner by default. Scheduled searches are always run as owner by the report scheduler. 
---
What goes around comes around. If it helps, hit it with Karma 🙂
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...