The names of the investigators are populated in the KV Store, user_realnames, Here are steps that needs to be taken for removing the old investigators.
Hi @fahimeh ,
ES hasn't its own authentication method, it uses users from Splunk Enterprise, it only has its own roles.
If you delete an user in Splunk Enterprise its isn't possible for that user access the system, but probably the investigation and action from tha user continue to remain in the system, even if if you search an object created by that user you find an orphaned object.
Ciao.
Giuseppe
The names of the investigators are populated in the KV Store, user_realnames, Here are steps that needs to be taken for removing the old investigators.