Security

reassigning ownership for large amount of knowledge objects

sbattista09
Contributor

I see that when i reassigning ownership the schedule wont kick in (next_scheduled_time just reads none), for example until i open the search and manually hit save it seems like none of them will run on the original set time.

anyone ever run into this before? is there a rest call i can do to change the ownership based off the old owner?

0 Karma

harsmarvania57
Ultra Champion

Hi,

Here you go for bulk modification of ownership of KO https://github.com/harsmarvania57/splunk-ko-change . Script given in Github repo works with python2 only, I am in process to convert that script for python3 and will be going to do some enhancement.

0 Karma

nickhills
Ultra Champion

Sometimes I have noticed the UI does not always immediately calculate the next run date, but it does schedule correctly.

If you come back later, the UI updates and then the time is calculated correctly.
Also restarting Splunk seems to force it to refresh immediately

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...