- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Changing permission of a private knowledge object makes all access inaccessible
![burwell burwell](https://community.splunk.com/legacyfs/online/avatars/220453.jpg)
burwell
![SplunkTrust SplunkTrust](/html/@E48BE65924041B382F8C3220FF058B38/rank_icons/splunk-trust-16.png)
SplunkTrust
01-19-2022
11:57 AM
Scenario on a SHC, Splunk 8.2.2.1
- user1 and user2 are 2 users in role user
- user1 who is in role user owns a private extraction (and saved searches). she is leaving the company and wants user2 to now own the knowledge object
- admin does a reassign knowledge objects of all knowledge objects from user1 -> user2 (and yes they probably got the warning that this might make knowledge objects inaccessible)
- now no one including admin can access this knowledge object from the UI or curl .. /services/configs/conf-props/extractnamehere/acl
- Fortunately: the props.conf file in /opt/splunk/etc/users/user1/search/local/props.conf is still there
Is there any other way the admin could gain access to this knowledge object other than grabbing the configs off the file system of the Splunk head?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo
![SplunkTrust SplunkTrust](/html/@E48BE65924041B382F8C3220FF058B38/rank_icons/splunk-trust-16.png)
SplunkTrust
01-19-2022
10:45 PM
You should see those via Settings -> All configurations. If I recall right this is the only place in GUI (or at least which I have found) where the one can see users' private KOs.
r. Ismo
r. Ismo
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SinghK
Builder
01-19-2022
10:39 PM
Did you check if the object is showing under orphaned objects?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![burwell burwell](https://community.splunk.com/legacyfs/online/avatars/220453.jpg)
burwell
![SplunkTrust SplunkTrust](/html/@E48BE65924041B382F8C3220FF058B38/rank_icons/splunk-trust-16.png)
SplunkTrust
01-20-2022
10:08 AM
The object doesn't show under "All configurations"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SinghK
Builder
01-21-2022
02:15 AM
you can try what Ismo said about creating the same user(exact user id that existed) locally on splunk. I have done that before same issue as you described and then it let le me reassign object to other user.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![burwell burwell](https://community.splunk.com/legacyfs/online/avatars/220453.jpg)
burwell
![SplunkTrust SplunkTrust](/html/@E48BE65924041B382F8C3220FF058B38/rank_icons/splunk-trust-16.png)
SplunkTrust
01-21-2022
10:04 AM
Hi. Thanks for the responses.
So as an experiment with my two users.. I never removed the first user. I login locally and that user does not see their knowledge object (extract) BUT it is there on the local disk. So the meta data is gone I guess.
We had this happen on a SHC so I repo'd on a standalone head. I can totally reproduce this.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
isoutamo
![SplunkTrust SplunkTrust](/html/@E48BE65924041B382F8C3220FF058B38/rank_icons/splunk-trust-16.png)
SplunkTrust
01-20-2022
11:42 PM
Can you try to create temporarily user1 as local on this SHC and see if those KOs are then available and can be copied/assigned again to user2?
![](/skins/images/53C7C94B4DD15F7CACC6D77B9B4D55BF/responsive_peak/images/icon_anonymous_message.png)