What is the best way to move a set of saved searches from one ldap user to a local splunk account without restarting Splunk service?
curl -k -u admin:thepwd https://your_splunk_server:8089/servicesNS/CURRENT_OWNER/SPLUNK_APP_WHERE_SEARCH_EXISTS/saved/search... -d owner=NEW_LOCAL_USER -d sharing=app
View solution in original post
Thank you. It does the job.