Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Search History

SeoaneR
Explorer

Hi there

Just wondering if it's possible to delete/remove searches from your search history list.

Looking to manage/tidy up the search history panel

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @SeoaneR 

Just to clarify, you're looking for delete search history in the "Search History" dropdown on the front page of the search view? If so please see my other response, and be mindful of other responses in this thread which point to the "delete" command which may delete data in your indexes!!


 Ultimately:

Try looking in $SPLUNK_HOME/etc/users/USERNAME/APPNAME/history/ for the history files for a user, typically you'll want to check in the search app if this is the default for the user.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

SeoaneR
Explorer

Hi Will

 

Thanks for coming back to me .

I followed an instruction from another use about going into /opt/splunk/etc/users/admin/search/history

I then opened a .csv file under my name with vim  and started to delete entries.

This has reduced the amount of searches from the "Search History"  window pane in the User Interface of splunk.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@SeoaneR 

see this answer https://community.splunk.com/t5/Splunk-Search/How-to-clear-search-history/m-p/392454/highlight/true 

  • Each user has it's own private search history.
  • Try finding it at the following path
  • /opt/splunk/etc/users/<nameofuser>/search/
  • Open the CSV file and manually remove the entries you no longer need.
  • Save the file after making changes.
  • You can delete the entire CSV file to clear all search history for a specific user.

kiran_panchavat_0-1741691281117.png

If you need to delete specific events from your Splunk data, you can use the delete command in your search query. For example:

index=web_app status=505 | delete

This will remove events matching the specified criteria

Removing data by using delete command in Splunk SPL Query | Splunk 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

SeoaneR
Explorer

That was very useful , many thanks

It has shrunk my search history considerable and beginning to look more manageable.

 

kiran_panchavat
SplunkTrust
SplunkTrust

@SeoaneR  Great! I hope this is helpful for you. If so, please accept the solution.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @SeoaneR 

Try looking in $SPLUNK_HOME/etc/users/USERNAME/APPNAME/history/ for the history files for a user, typically you'll want to check in the search app if this is the default for the user.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...