Splunk Dev

No search history for clean install of 8.01 Enterprise

dkozinn
Path Finder

I have a fresh install of Splunk Enterprise 8.01 on a box running Ubuntu 19.10 as a standalone instance (no clustering, etc.) When I access the Search app, there is never any history showing under Search History. Using |history as a search does not product any output either. If I look in /opt/splunk/etc/users/myuser/search/history there is a CSV file that gets updated with each search I enter. If I look at the _audit index, I do see the searches there.

I've looked through a few other posts here but none seems relevant. Any suggestions?

0 Karma

dkozinn
Path Finder

Trying to bump for visibility. Still happens after upgrading to 8.0.3.

The only thing I noticed that might be unusual (and I don't know if it is) is that the permissions on the CSV file are that it's set to 0600 and owned by root. The directory itself and the only other file there (called .dummy_history) are all owned by splunk:splunk. If I change the ownership of the .csv to be splunk:splunk it changes back to root.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...