Reporting

What is the purpose of setting scheduled search to "RUN AS USER"?

the_wolverine
Champion

Looking for clarification. I have users without scheduling capability who ask me to schedule their saved search. I can go through the motions and set these (as the admin user), save my changes, however the scheduled search actually never runs because the user doesn't have the capability to schedule.

What is the point of allowing me to configure these settings if the user doesn't have the capability?

And what does setting Run as "owner" vs "user" do? My original guess was that the search can be scheduled to run as the user who was scheduling it (me) but clearly that would be too convenient....

renjith_nair
Legend

We also had the same requirement and same issue. From the documents it's just about restricting the permissions on the data and object permissions (Reference : http://docs.splunk.com/Documentation/Splunk/6.3.1511/Report/Createandeditreports#Determine_whether_t...)

Determine whether to run reports as the report owner or report user

When you share a report with other users, you have the option of having it run as the report owner (the person who created the report) or the report "user" (the person who is running the report). This setting is used for two reasons:

    It can allow access to search data that might otherwise be unavailable to the person running the report.
    It helps prevent situations where your concurrent search limit is being hit when too many people run reports that you own. 

Searches run as owner by default. Scheduled searches are always run as owner by the report scheduler. 
---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...