Security

reassigning ownership for large amount of knowledge objects

sbattista09
Contributor

I see that when i reassigning ownership the schedule wont kick in (next_scheduled_time just reads none), for example until i open the search and manually hit save it seems like none of them will run on the original set time.

anyone ever run into this before? is there a rest call i can do to change the ownership based off the old owner?

0 Karma

harsmarvania57
Ultra Champion

Hi,

Here you go for bulk modification of ownership of KO https://github.com/harsmarvania57/splunk-ko-change . Script given in Github repo works with python2 only, I am in process to convert that script for python3 and will be going to do some enhancement.

0 Karma

nickhills
Ultra Champion

Sometimes I have noticed the UI does not always immediately calculate the next run date, but it does schedule correctly.

If you come back later, the UI updates and then the time is calculated correctly.
Also restarting Splunk seems to force it to refresh immediately

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...