What is the best way to move a set of saved searches from one ldap user to a local splunk account without restarting Splunk service?
Thanks,
Lp
curl -k -u admin:thepwd https://your_splunk_server:8089/servicesNS/CURRENT_OWNER/SPLUNK_APP_WHERE_SEARCH_EXISTS/saved/search... -d owner=NEW_LOCAL_USER -d sharing=app
curl -k -u admin:thepwd https://your_splunk_server:8089/servicesNS/CURRENT_OWNER/SPLUNK_APP_WHERE_SEARCH_EXISTS/saved/search... -d owner=NEW_LOCAL_USER -d sharing=app
Thank you. It does the job.
Lp