Security

Can you answer my question regarding managing orphaned knowledge objects.?

yutaka1005
Builder

There are descriptions on managing orphaned knowledge objects after deletion of users, for reasons such as change of operator in the following manuals.

http://docs.splunk.com/Documentation/Splunk/7.2.1/Knowledge/Resolveorphanedsearches

And It has the following description in it.

-----Manual reference-----

The Reassign Knowledge Objects page, in Settings, is the only orphaned knowledge object detection method that can find all orphaned knowledge object types. It can only find orphaned knowledge objects that have been shared at the app or global levels.

In other words, knowledge objects with private privileges can not be found.

However, if a knowledge object is with privileges of app or global, admin can see it and can also change the authority of it.

Even if only the role of deleted user is set to allow read and write.

  1. If so, what is this function for?

  2. Also is there way to discover orphaned objects with private privileges from Splunk Web and reassign them to some other users?

I would appreciate it if you let me know.

0 Karma
1 Solution

yutaka1005
Builder

I found it in below chapter in manual.

Reassign unshared, orphaned knowledge objects

I understood that I can't discover orphaned objects with private privileges and reassign them to some other users in Reassign Knowledge Objects page in Settings.

Instead, I have to recreate deleted user, or copy stanza to other .conf file.

View solution in original post

0 Karma

yutaka1005
Builder

I found it in below chapter in manual.

Reassign unshared, orphaned knowledge objects

I understood that I can't discover orphaned objects with private privileges and reassign them to some other users in Reassign Knowledge Objects page in Settings.

Instead, I have to recreate deleted user, or copy stanza to other .conf file.

0 Karma

dkeck
Influencer

Normally you would mark the answer as accepted that provided a solution, not your comment that this solution helped..

0 Karma

dkeck
Influencer
0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...