Security

What needs to be done when ldap user is deactivated?

the_wolverine
Champion

If we have an ldap user that is deactivated, what happens to all of his scheduled searches and other user content like views, tags, field extractions?

Has someone come up with steps or a script to migrate all content for a disabled user to another user?

0 Karma

jworthington_sp
Splunk Employee
Splunk Employee

There isn't a script that I'm aware of, but perhaps this info might be useful:

http://splunk-base.splunk.com/answers/44677/delete-owner-of-scheduled-searches

Hope that helps!

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...