Splunk Dev

No "scheduled time" for my saved searches

sylim_splunk
Splunk Employee
Splunk Employee

Saved Searches not keeping configuration while changing owner by REST as below;

curl -k -u admin:changeme https://SH:8089/servicesNS/"owner name"/"app name"/saved/searches//acl -d owner=newOwner -d sharing=user 

After replace some ownership from Alerts I saw those Alerts have lost their scheduled time - they have all "none" in the list. Therefore I tried to open and saving one by one I realised those Alerts had scheduled again.
When I do the same action to the others the REST had lost them again!

Tags (1)
1 Solution

sylim_splunk
Splunk Employee
Splunk Employee

It appears all good now after the reload command for saved searches - the changes seems not recognized by the Splunk until it gets reloaded. Make sure to run below after changes to the scheduled searches as best practice.

./splunk _internal call /servicesNS/newOwner/AppName/saved/searches/_reload

View solution in original post

sylim_splunk
Splunk Employee
Splunk Employee

It appears all good now after the reload command for saved searches - the changes seems not recognized by the Splunk until it gets reloaded. Make sure to run below after changes to the scheduled searches as best practice.

./splunk _internal call /servicesNS/newOwner/AppName/saved/searches/_reload

woodcock
Esteemed Legend

You should click Accept on your answer to close the question.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...