There are descriptions on managing orphaned knowledge objects after deletion of users, for reasons such as change of operator in the following manuals.
http://docs.splunk.com/Documentation/S...
Hi everyone, I'm looking for a search, that shows me when the health status of splunkd is changing from green to yellow or red... Would that be possible?
I have a task to move All users (except admins, nobody) KOs (Knowledge Objects) from search app, to their own apps. When I try to move the KO, I get below error. Replication-related issue: Cannot m...
I'm a Splunk administrator, not a Windows administrator, so my Windows knowledge is limited. Nonetheless, many teams can benefit from having Windows Event Log data in Splunk. What are the best p...
index=MyApp | stats count by supportGroup, severity
That search provides me a list of events and the severity associated with the events. The severity comes up as 1,2,3,4 or 5. Is there a way fo...
I have created a dashboard to show the execution history of scheduled jobs which had ran. I used the logs from "index=_internal sourcetype=scheduler". This gives me the past run of all the scheduled...
Does anyone know of a rest call that can be used to kill all adhoc queries for a user? I do not wish to all users searches, nor do I want to kill schedule searches for that user. I have the fo...