Splunk Enterprise

Is it possible to have alerts and reports assigned to nobody as owner?

Gregski11
Contributor

would there ever be a scenario where its acceptable to have enabled alerts and or reports running which are not assigned to anybody ie owner = Nobody

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it is possible to have alerts and reports owned by 'nobody', but I don't know why you'd want to do that.  User 'nobody' uses default settings, which may not be correct for the use case.  IMO, it's better to assign alerts and reports to a service account with a role that has the resources needed to run  those alerts and reports.

---
If this reply helps you, Karma would be appreciated.

Gregski11
Contributor

thank you Rich for taking the time to comment, I agree with you however please check your own config as what I see is that Splunk runs it's own apps as Nobody, for example these:

Splunk_Security_Essentials

SplunkAppForWebAnalytics

Splunk_ML_Toolkit

Splunk_TA_microsoft-cloudservices

Splunk_TA_microsoft-sqlserver

splunk_instrumentation

search

splunk_monitoring_console

sideview_utils

simple_xml_examples

splunk_archiver

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I understand the use of Nobody is commonplace, but that doesn't mean it's a good idea or that I agree with it.

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust

Here is explanation what nobody actually means https://community.splunk.com/t5/All-Apps-and-Add-ons/Disambiguation-of-the-meaning-of-quot-nobody-qu...

Based on that, you should always use valid user to own those KOs. User could be a real user or service user depending on your needs.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...