Splunk Dev

No search history for clean install of 8.01 Enterprise

dkozinn
Path Finder

I have a fresh install of Splunk Enterprise 8.01 on a box running Ubuntu 19.10 as a standalone instance (no clustering, etc.) When I access the Search app, there is never any history showing under Search History. Using |history as a search does not product any output either. If I look in /opt/splunk/etc/users/myuser/search/history there is a CSV file that gets updated with each search I enter. If I look at the _audit index, I do see the searches there.

I've looked through a few other posts here but none seems relevant. Any suggestions?

0 Karma

dkozinn
Path Finder

Trying to bump for visibility. Still happens after upgrading to 8.0.3.

The only thing I noticed that might be unusual (and I don't know if it is) is that the permissions on the CSV file are that it's set to 0600 and owned by root. The directory itself and the only other file there (called .dummy_history) are all owned by splunk:splunk. If I change the ownership of the .csv to be splunk:splunk it changes back to root.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...