Splunk Cloud Platform

Workload Management Rule - No AllTime searches

jeremiahMN
Explorer

I'm following the example provided here.
https://docs.splunk.com/Documentation/Splunk/9.0.2/Workloads/AdmissionRules#Example_admission_rules

search_time_range=alltime AND (NOT role=sc_admin) AND (NOT app=splunk_instance_monitoring)

However when I look in the monitoring console it shows that it's blocking some things that I believe are built in searches. (we use splunk cloud)
Cleanup Models For Predictive Analytics
itsi_content_packs_status_update
Telemetry - Inputs
itsi_event_grouping
Telemetry - Volume

All of these things have user as "nobody". I tried to add AND (NOT user=nobody) to my workload rule, but tells me.
validation failed with error=invalid value of predicate 'user'

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...