Security

reassigning ownership for large amount of knowledge objects

sbattista09
Contributor

I see that when i reassigning ownership the schedule wont kick in (next_scheduled_time just reads none), for example until i open the search and manually hit save it seems like none of them will run on the original set time.

anyone ever run into this before? is there a rest call i can do to change the ownership based off the old owner?

0 Karma

harsmarvania57
Ultra Champion

Hi,

Here you go for bulk modification of ownership of KO https://github.com/harsmarvania57/splunk-ko-change . Script given in Github repo works with python2 only, I am in process to convert that script for python3 and will be going to do some enhancement.

0 Karma

nickhills
Ultra Champion

Sometimes I have noticed the UI does not always immediately calculate the next run date, but it does schedule correctly.

If you come back later, the UI updates and then the time is calculated correctly.
Also restarting Splunk seems to force it to refresh immediately

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...