A method previously used with SH Pooling no longer seems to work for search heads in a search head cluster. In the documentation, for changing object ownership, it advises changing the owner of the object, but does not indicate how to do it:
http://docs.splunk.com/Documentation/Splunk/6.2.5/Security/BestpracticeforremovinganLDAPuser
> 3. For any searches or objects that the user owns, change the owner. You
> change it an admin user or maintenance
> account, or whatever you prefer.
(The grammar is also incorrect 🙂
... View more