I was looking for option where i can change ownership of alerts/searches/dashboards from application if i have admin/power rights.
in my organization, we don't have splunk home directory rights as that is deployed on different server but we have admin rights.
is there any other way except change owner in $SPLUNK_HOME/etc/apps//metadata/local.meta file? if not then is it possible that this feature can come in Splunk future version?
Regards
Sachin
NEW FEATURE ALERT!
As of Splunk 6.6, you can now do this from the Search Head GUI with the new Reassign Knowledge Objects
feature:
https://docs.splunk.com/Documentation/SplunkCloud/6.6.0/ReleaseNotes/NewSplunkCloudFeatures
https://www.splunk.com/blog/2017/05/02/what-s-new-in-splunk-enterprise-6-6-and-splunk-cloud.html
You can also do this from the REST API:
https://wiki.splunk.com/Community:How_to_change_owner_of_savedsearches_using_REST_API