Splunk Version: 6.5.2
I receive a notification for a list of orphaned searches owned by a disabled user. I have changed the owner and restarted Splunk, but it still shows up in the list of orphaned searches and still displays the original owner.
Example:
search name: scheduled_search_test
owner: oldowner
app: sysadmin
sharing: user
status: enabled
I modified /$SPLUNK_HOME/etc/apps/sysadmin/metadata/local.meta to change "oldowner" to "newowner" and restarted Splunk, but the search still shows up as orphaned and owned by "oldowner". Any suggestions would be greatly appreciated.
... View more