Splunk Search

How to disable all searches for a user?

GeorgeStarkey
Path Finder

We have a user that is no longer here, however all saved searches are still trying to run.

This causes a lot of "Failed to get LDAP" errors, and I assume is part of a performance issue I am seeing.

Since, there are not other members of this users team complaining that these searches are not firing, I want to just disable them, but not completely remove yet.

Can this be done in bulk?

Tags (3)
1 Solution

lguinn2
Legend

If you are the admin, you can go to Settings -> Searches, reports, and alerts and then choose the user from the Owner drop-down. Click "Disable" for each of the searches. That should do it.

View solution in original post

GeorgeStarkey
Path Finder

A good feature would be to be able to enable/disable everything owned by a user.

lguinn2
Legend

@GeorgeStarkey - agreed! And you can make a formal enhancement request here:

http://www.splunk.com/index.php/submit_issue

Enter it just like a support ticket, but choose the "enhancement" option.

0 Karma

lguinn2
Legend

If you are the admin, you can go to Settings -> Searches, reports, and alerts and then choose the user from the Owner drop-down. Click "Disable" for each of the searches. That should do it.

GeorgeStarkey
Path Finder

Yes. But my question is how to do this in bulk. This user has many searches. And this will not be a once only problem.

0 Karma

lguinn2
Legend

There is no way to do this in bulk from the Splunk UI.

It is not trivial to write a script for this, as you need to examine savedsearches.conf and the corresponding local.meta files over all the apps as well as the user's private directories.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...