I'm following the example provided here.
https://docs.splunk.com/Documentation/Splunk/9.0.2/Workloads/AdmissionRules#Example_admission_rules
search_time_range=alltime AND (NOT role=sc_admin) AND (NOT app=splunk_instance_monitoring)
However when I look in the monitoring console it shows that it's blocking some things that I believe are built in searches. (we use splunk cloud)
Cleanup Models For Predictive Analytics
itsi_content_packs_status_update
Telemetry - Inputs
itsi_event_grouping
Telemetry - Volume
All of these things have user as "nobody". I tried to add AND (NOT user=nobody) to my workload rule, but tells me.
validation failed with error=invalid value of predicate 'user'