<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search History in Feedback</title>
    <link>https://community.splunk.com/t5/Feedback/Search-History/m-p/741400#M504</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308405"&gt;@SeoaneR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see this answer &lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-clear-search-history/m-p/392454/highlight/true" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-clear-search-history/m-p/392454/highlight/true&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Each user has it's own private search history.&lt;/LI&gt;&lt;LI&gt;Try finding it at the following path&lt;/LI&gt;&lt;LI&gt;/opt/splunk/etc/users/&amp;lt;nameofuser&amp;gt;/search/&lt;/LI&gt;&lt;LI&gt;Open the CSV file and manually remove the entries you no longer need.&lt;/LI&gt;&lt;LI&gt;Save the file after making changes.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;You can delete the entire CSV file to clear all search history for a specific user.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1741691281117.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38084i2BBDBAA738E7B9B4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1741691281117.png" alt="kiran_panchavat_0-1741691281117.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you need to delete specific events from your Splunk data, you can use the&amp;nbsp;&lt;/SPAN&gt;delete&lt;SPAN&gt;&amp;nbsp;command in your search query. For example:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;index=web_app status=505 | delete&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;This will remove events matching the specified criteria&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Delete-command" target="_blank" rel="noopener"&gt;Removing data by using delete command in Splunk SPL Query | Splunk&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Mar 2025 11:09:43 GMT</pubDate>
    <dc:creator>kiran_panchavat</dc:creator>
    <dc:date>2025-03-11T11:09:43Z</dc:date>
    <item>
      <title>Search History</title>
      <link>https://community.splunk.com/t5/Feedback/Search-History/m-p/741395#M502</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;Just wondering if it's possible to delete/remove searches from your search history list.&lt;/P&gt;&lt;P&gt;Looking to manage/tidy up the search history panel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 09:58:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Search-History/m-p/741395#M502</guid>
      <dc:creator>SeoaneR</dc:creator>
      <dc:date>2025-03-11T09:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Search History</title>
      <link>https://community.splunk.com/t5/Feedback/Search-History/m-p/741396#M503</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308405"&gt;@SeoaneR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Try looking in&amp;nbsp;&lt;/SPAN&gt;$SPLUNK_HOME/etc/users/USERNAME/APPNAME/history/&lt;SPAN&gt;&amp;nbsp;for the history files for a user, typically you'll want to check in the search app if this is the default for the user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 10:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Search-History/m-p/741396#M503</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-11T10:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Search History</title>
      <link>https://community.splunk.com/t5/Feedback/Search-History/m-p/741400#M504</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308405"&gt;@SeoaneR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see this answer &lt;A href="https://community.splunk.com/t5/Splunk-Search/How-to-clear-search-history/m-p/392454/highlight/true" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/How-to-clear-search-history/m-p/392454/highlight/true&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Each user has it's own private search history.&lt;/LI&gt;&lt;LI&gt;Try finding it at the following path&lt;/LI&gt;&lt;LI&gt;/opt/splunk/etc/users/&amp;lt;nameofuser&amp;gt;/search/&lt;/LI&gt;&lt;LI&gt;Open the CSV file and manually remove the entries you no longer need.&lt;/LI&gt;&lt;LI&gt;Save the file after making changes.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;You can delete the entire CSV file to clear all search history for a specific user.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1741691281117.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38084i2BBDBAA738E7B9B4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1741691281117.png" alt="kiran_panchavat_0-1741691281117.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you need to delete specific events from your Splunk data, you can use the&amp;nbsp;&lt;/SPAN&gt;delete&lt;SPAN&gt;&amp;nbsp;command in your search query. For example:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;index=web_app status=505 | delete&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;This will remove events matching the specified criteria&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunk.my.site.com/customer/s/article/Delete-command" target="_blank" rel="noopener"&gt;Removing data by using delete command in Splunk SPL Query | Splunk&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 11:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Search-History/m-p/741400#M504</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-11T11:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: Search History</title>
      <link>https://community.splunk.com/t5/Feedback/Search-History/m-p/741409#M505</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308405"&gt;@SeoaneR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to clarify, you're looking for delete search history in the "Search History" dropdown on the front page of the search view? If so please see my other response, and be mindful of other responses in this thread which point to the "delete" command which may delete data in your indexes!!&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;Ultimately:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Try looking in&amp;nbsp;&lt;/SPAN&gt;$SPLUNK_HOME/etc/users/USERNAME/APPNAME/history/&lt;SPAN&gt;&amp;nbsp;for the history files for a user, typically you'll want to check in the search app if this is the default for the user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 13:52:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Search-History/m-p/741409#M505</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-11T13:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Search History</title>
      <link>https://community.splunk.com/t5/Feedback/Search-History/m-p/741459#M506</link>
      <description>&lt;P&gt;That was very useful , many thanks&lt;/P&gt;&lt;P&gt;It has shrunk my search history considerable and beginning to look more manageable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 20:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Search-History/m-p/741459#M506</guid>
      <dc:creator>SeoaneR</dc:creator>
      <dc:date>2025-03-11T20:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Search History</title>
      <link>https://community.splunk.com/t5/Feedback/Search-History/m-p/741716#M508</link>
      <description>&lt;P&gt;Hi Will&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for coming back to me .&lt;/P&gt;&lt;P&gt;I followed an instruction from another use about going into /opt/splunk/etc/users/admin/search/history&lt;/P&gt;&lt;P&gt;I then opened a .csv file under my name with vim&amp;nbsp; and started to delete entries.&lt;/P&gt;&lt;P&gt;This has reduced the amount of searches from the "Search History"&amp;nbsp; window pane in the User Interface of splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 16:20:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Search-History/m-p/741716#M508</guid>
      <dc:creator>SeoaneR</dc:creator>
      <dc:date>2025-03-13T16:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Search History</title>
      <link>https://community.splunk.com/t5/Feedback/Search-History/m-p/741756#M509</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/308405"&gt;@SeoaneR&lt;/a&gt;&amp;nbsp; Great! I hope this is helpful for you. If so, please accept the solution.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 05:07:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Feedback/Search-History/m-p/741756#M509</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-03-14T05:07:55Z</dc:date>
    </item>
  </channel>
</rss>

