I have a dashboard that depends on multiple summary indexes, all of which have global permissions. The summary indexes are owned by user no longer in our Splunk system. When I attempt to enable these indexes, they disable at the next scheduled run. I have admin privileges, but I don't see how I can change the owner without re-creating the searches (there are too many to do this).
Why won't Splunk run scheduled searches because they were created by a former user?
Is there a relatively painless way to change the owner? I'm guessing there is a file on the server that can be edited, but why not an in-app solution?
I'm running 4.1.5 and need a fix without upgrading to 4.2 (which doesn't appear to have fixed the problem).
... View more