Hi everyone, I'm currently facing an issue that I have not been able to resolve and would appreciate your guidance. We have a Search Head Cluster environment where we created several custom alerts (saved searches). These objects were stored in the Enterprise Security application (`SplunkEnterpriseSecuritySuite`). The user who originally created these alerts left the company, so the ownership of these objects was reassigned to the `admin` user. Now we need to remove some of these alerts, but we are unable to delete them, even though our current user has the `admin` role. I would like to understand if this behavior is expected: - Is there any special behavior for knowledge objects owned by the `admin` user? - Does the `admin` role have any limitation when trying to delete objects owned by `admin`? - Could this behavior be related to the Search Head Cluster configuration or object replication? - Is there any specific capability required to delete saved searches owned by another user? I also tried to reproduce a similar scenario in another Search Head Cluster environment, but there I was able to delete objects owned by `admin`, so I am not sure if this is related to a specific configuration, permission, or Enterprise Security setting. Any guidance or suggestions on where to investigate would be greatly appreciated. Thank you!
... View more