Splunk Search

How to delete search history?

pipg
Observer

Hello community,

Can anyone advise if it's possible to delete my search history? I'd like to delete old searches that serve no value e.g., those that returned no results, failed (i.e., were test searches while learning) or are duplicates etc.

I've searched helps docs and forums without luck. 

Thank you for your help in advance.

Pietra

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @pipg,

see this answer https://community.splunk.com/t5/Splunk-Search/How-to-clear-search-history/m-p/392454/highlight/true

in few words, in $SPLUNK_HOME/etc/users/<your_user>/<your_app>/history you can find a csv with your history.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...