Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Search History

SeoaneR
Explorer

Hi there

Just wondering if it's possible to delete/remove searches from your search history list.

Looking to manage/tidy up the search history panel

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @SeoaneR 

Just to clarify, you're looking for delete search history in the "Search History" dropdown on the front page of the search view? If so please see my other response, and be mindful of other responses in this thread which point to the "delete" command which may delete data in your indexes!!


 Ultimately:

Try looking in $SPLUNK_HOME/etc/users/USERNAME/APPNAME/history/ for the history files for a user, typically you'll want to check in the search app if this is the default for the user.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

SeoaneR
Explorer

Hi Will

 

Thanks for coming back to me .

I followed an instruction from another use about going into /opt/splunk/etc/users/admin/search/history

I then opened a .csv file under my name with vim  and started to delete entries.

This has reduced the amount of searches from the "Search History"  window pane in the User Interface of splunk.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@SeoaneR 

see this answer https://community.splunk.com/t5/Splunk-Search/How-to-clear-search-history/m-p/392454/highlight/true 

  • Each user has it's own private search history.
  • Try finding it at the following path
  • /opt/splunk/etc/users/<nameofuser>/search/
  • Open the CSV file and manually remove the entries you no longer need.
  • Save the file after making changes.
  • You can delete the entire CSV file to clear all search history for a specific user.

kiran_panchavat_0-1741691281117.png

If you need to delete specific events from your Splunk data, you can use the delete command in your search query. For example:

index=web_app status=505 | delete

This will remove events matching the specified criteria

Removing data by using delete command in Splunk SPL Query | Splunk 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

SeoaneR
Explorer

That was very useful , many thanks

It has shrunk my search history considerable and beginning to look more manageable.

 

kiran_panchavat
SplunkTrust
SplunkTrust

@SeoaneR  Great! I hope this is helpful for you. If so, please accept the solution.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @SeoaneR 

Try looking in $SPLUNK_HOME/etc/users/USERNAME/APPNAME/history/ for the history files for a user, typically you'll want to check in the search app if this is the default for the user.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...