Running the curl command noted in the docs:https://docs.splunk.com/Documentation/Splunk/6.5.0/Knowledge/Resolveorphanedsearches
On my search head captain:
curl -k -u uname:pass :/servicesNS///saved/searches//acl -d owner=newOwner -d sharing=user
I get back:User does not exist: user
YES I REALIZE THAT
but on my search heads, I can still find that user in SPLUNKHOME/etc/users/
So how can this user exist and not exist and how can I reassign the search?
Thanks!
↧