Splunk Search

remove orphaned scheduled search in Splunk 6.5.3

asimagu
Builder

hi

we have Splunk connected to Active Directory and we cannot add local users so we cannot reassign orphaned searches in order to delete them.

is there a way to delete them without reassigning them??

thanks

0 Karma

woodcock
Esteemed Legend

Any user with admin role should be able to delete them. You definitely should have at least 1 admin.

0 Karma

lguinn2
Legend

You can manually edit savedsearches.conf and local.meta to remove the stanzas.

You will need to identify the app that has these searches, to locate the appropriate configuration files.

Be sure to take a backup first!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...