I am removing a large group of users that own things in my Splunk and I am wondering if there is a best approach to changing object ownership?
Are there any disadvantages to just removing the local.meta lines with users that are being removed so that the owner appears as "nobody"? Or should I be changing these objects to a new user as the owner?
Also- do I have to restart Splunk after making changes to local.meta or can I just run server:8000/en-US/debug/refresh?
↧