Splunk Dev

No search history for clean install of 8.01 Enterprise

dkozinn
Path Finder

I have a fresh install of Splunk Enterprise 8.01 on a box running Ubuntu 19.10 as a standalone instance (no clustering, etc.) When I access the Search app, there is never any history showing under Search History. Using |history as a search does not product any output either. If I look in /opt/splunk/etc/users/myuser/search/history there is a CSV file that gets updated with each search I enter. If I look at the _audit index, I do see the searches there.

I've looked through a few other posts here but none seems relevant. Any suggestions?

0 Karma

dkozinn
Path Finder

Trying to bump for visibility. Still happens after upgrading to 8.0.3.

The only thing I noticed that might be unusual (and I don't know if it is) is that the permissions on the CSV file are that it's set to 0600 and owned by root. The directory itself and the only other file there (called .dummy_history) are all owned by splunk:splunk. If I change the ownership of the .csv to be splunk:splunk it changes back to root.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...