Reporting

What is the purpose of setting scheduled search to "RUN AS USER"?

the_wolverine
Champion

Looking for clarification. I have users without scheduling capability who ask me to schedule their saved search. I can go through the motions and set these (as the admin user), save my changes, however the scheduled search actually never runs because the user doesn't have the capability to schedule.

What is the point of allowing me to configure these settings if the user doesn't have the capability?

And what does setting Run as "owner" vs "user" do? My original guess was that the search can be scheduled to run as the user who was scheduling it (me) but clearly that would be too convenient....

renjith_nair
Legend

We also had the same requirement and same issue. From the documents it's just about restricting the permissions on the data and object permissions (Reference : http://docs.splunk.com/Documentation/Splunk/6.3.1511/Report/Createandeditreports#Determine_whether_t...)

Determine whether to run reports as the report owner or report user

When you share a report with other users, you have the option of having it run as the report owner (the person who created the report) or the report "user" (the person who is running the report). This setting is used for two reasons:

    It can allow access to search data that might otherwise be unavailable to the person running the report.
    It helps prevent situations where your concurrent search limit is being hit when too many people run reports that you own. 

Searches run as owner by default. Scheduled searches are always run as owner by the report scheduler. 
Happy Splunking!
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...