Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Search History

SeoaneR
Explorer

Hi there

Just wondering if it's possible to delete/remove searches from your search history list.

Looking to manage/tidy up the search history panel

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @SeoaneR 

Just to clarify, you're looking for delete search history in the "Search History" dropdown on the front page of the search view? If so please see my other response, and be mindful of other responses in this thread which point to the "delete" command which may delete data in your indexes!!


 Ultimately:

Try looking in $SPLUNK_HOME/etc/users/USERNAME/APPNAME/history/ for the history files for a user, typically you'll want to check in the search app if this is the default for the user.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

SeoaneR
Explorer

Hi Will

 

Thanks for coming back to me .

I followed an instruction from another use about going into /opt/splunk/etc/users/admin/search/history

I then opened a .csv file under my name with vim  and started to delete entries.

This has reduced the amount of searches from the "Search History"  window pane in the User Interface of splunk.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@SeoaneR 

see this answer https://community.splunk.com/t5/Splunk-Search/How-to-clear-search-history/m-p/392454/highlight/true 

  • Each user has it's own private search history.
  • Try finding it at the following path
  • /opt/splunk/etc/users/<nameofuser>/search/
  • Open the CSV file and manually remove the entries you no longer need.
  • Save the file after making changes.
  • You can delete the entire CSV file to clear all search history for a specific user.

kiran_panchavat_0-1741691281117.png

If you need to delete specific events from your Splunk data, you can use the delete command in your search query. For example:

index=web_app status=505 | delete

This will remove events matching the specified criteria

Removing data by using delete command in Splunk SPL Query | Splunk 

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!

SeoaneR
Explorer

That was very useful , many thanks

It has shrunk my search history considerable and beginning to look more manageable.

 

kiran_panchavat
SplunkTrust
SplunkTrust

@SeoaneR  Great! I hope this is helpful for you. If so, please accept the solution.

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @SeoaneR 

Try looking in $SPLUNK_HOME/etc/users/USERNAME/APPNAME/history/ for the history files for a user, typically you'll want to check in the search app if this is the default for the user.

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...