Reporting

What is the purpose of setting scheduled search to "RUN AS USER"?

the_wolverine
Champion

Looking for clarification. I have users without scheduling capability who ask me to schedule their saved search. I can go through the motions and set these (as the admin user), save my changes, however the scheduled search actually never runs because the user doesn't have the capability to schedule.

What is the point of allowing me to configure these settings if the user doesn't have the capability?

And what does setting Run as "owner" vs "user" do? My original guess was that the search can be scheduled to run as the user who was scheduling it (me) but clearly that would be too convenient....

renjith_nair
Legend

We also had the same requirement and same issue. From the documents it's just about restricting the permissions on the data and object permissions (Reference : http://docs.splunk.com/Documentation/Splunk/6.3.1511/Report/Createandeditreports#Determine_whether_t...)

Determine whether to run reports as the report owner or report user

When you share a report with other users, you have the option of having it run as the report owner (the person who created the report) or the report "user" (the person who is running the report). This setting is used for two reasons:

    It can allow access to search data that might otherwise be unavailable to the person running the report.
    It helps prevent situations where your concurrent search limit is being hit when too many people run reports that you own. 

Searches run as owner by default. Scheduled searches are always run as owner by the report scheduler. 
---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...