What needs to be done when ldap user is deactivated?


If we have an ldap user that is deactivated, what happens to all of his scheduled searches and other user content like views, tags, field extractions?

Has someone come up with steps or a script to migrate all content for a disabled user to another user?

0 Karma

Splunk Employee
Splunk Employee

There isn't a script that I'm aware of, but perhaps this info might be useful:

Hope that helps!

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!