The nobody user means that there is no owner assigned to the object.
For example an app that includes reports in savedsearches.conf and doesn't include metadata with owner info...which is normal.
The search runs as splunk-system-user so it has admin like access
Thank u for your response. How do I find out what the object is? Should this "no body" ownership be changes or leave it the way it is please? Thanks again.
Settings -> All Configurations -> filter to owner of "No owner"
Or in various other places such as Settings -> Searches, reports, Alerts
Look for the owner of "nobody"
As mentioned they will run as splunk-system-user which uses the splunk-system-role, the role will be visible in Splunk but the user is hidden...
Personally I see no reason to change this from the nobody user *unless* you have a requirement to control quota and do not want to modify the splunk-sytem-role quotas...
In my environment I have not re-owned the nobody searches to an owner