Skip to main content

 

Splunk Lantern

Troubleshooting orphaned knowledge objects in Splunk Enterprise

 

Orphaned knowledge objects can occur when a user who created a search, dashboard, lookup, field, etc has left or moved and been deactivated in the Splunk instance. This leads to an error relating to orphaned objects, and can lead some objects such as lookups to break entirely.

Solution

You can utilise the "Orphaned Scheduled Searches, Reports and Alerts" dashboard to find out where orphaned knowledge objects are. This same information can be seen from the Messages section that you can review as an admin, however anyone with access to the Orphaned dashboard can review objects (which is useful if the person who left was your Splunk admin.)

This dashboard can be found in Search & Reporting under Dashboards. You might need to deselect filter options when looking at the list of dashboards to find it.

Now you know which ones are orphaned, you can work on reassigning them:

  1. Select Settings > All configurations.
  2. Click Reassign Knowledge Objects.
  3. Click Orphaned to filter out non-orphaned objects from the list.

You can now decide to reassign these to a new user, or delete them if they are no longer required.

Next steps

Somerford Associates is an award winning Elite Partner with Splunk and the largest Partner Practice of Consultants in EMEA. We protect data, demonstrate that it is being managed effectively and derive greater value, by providing real-time insights to support effective decision making. With our specialist knowledge, skills, experience and strong reputation for enabling digital transformation at scale and at pace, we provide full delivery, including design, implementation, deployment and support.

The user- and community-generated information, content, data, text, graphics, images, videos, documents and other materials made available on Splunk Lantern is Community Content as provided in the terms and conditions of the Splunk Website Terms of Use, and it should not be implied that Splunk warrants, recommends, endorses or approves of any of the Community Content, nor is Splunk responsible for the availability or accuracy of such. Splunk specifically disclaims any liability and any actions resulting from your use of any information provided on Splunk Lantern.