Hi,
We always run into the problem where people leave our organization, we delete their account in Splunk, but want to keep their automated reports and dashboards. Is there a smart solution to move one app/dashboard/scheduled search/field/whateverelement to a new owner?
Thank you in advance, Tom
Can this also applied for other Splunk elements like fields, macros etc?
The answer basically does a Splunk REST API endpoint POST call. See full list of Splunk API endpoints here.
http://docs.splunk.com/Documentation/Splunk/6.2.6/RESTREF/RESTlist