Splunk Dev

No search history for clean install of 8.01 Enterprise

dkozinn
Path Finder

I have a fresh install of Splunk Enterprise 8.01 on a box running Ubuntu 19.10 as a standalone instance (no clustering, etc.) When I access the Search app, there is never any history showing under Search History. Using |history as a search does not product any output either. If I look in /opt/splunk/etc/users/myuser/search/history there is a CSV file that gets updated with each search I enter. If I look at the _audit index, I do see the searches there.

I've looked through a few other posts here but none seems relevant. Any suggestions?

0 Karma

dkozinn
Path Finder

Trying to bump for visibility. Still happens after upgrading to 8.0.3.

The only thing I noticed that might be unusual (and I don't know if it is) is that the permissions on the CSV file are that it's set to 0600 and owned by root. The directory itself and the only other file there (called .dummy_history) are all owned by splunk:splunk. If I change the ownership of the .csv to be splunk:splunk it changes back to root.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...