Splunk Search

How to view a list of my most recent searches (search history)

mfrost8
Builder

This seems like it should be an easy question, but I haven't found the answer....

I ran a search recently and it had a lot of stuff in it but I never saved it. It wasn't something I thought I'd need to refer to later so that was no point in saving. I'm hoping it's still in my search history somewhere, but the only way I've ever interacted with my search history is when I've typed the first part of a search I've run before.

Is there some way to just tell Splunk to show me all the searches it's seen me run so I can find the one I'm looking for?

Thanks

Tags (1)
1 Solution

rdownie
Communicator

try the history command.


|history | head 20

or however many you want to see.

View solution in original post

rdownie
Communicator

try the history command.


|history | head 20

or however many you want to see.

mfrost8
Builder

Thanks very much, rdownie!

0 Karma

yeuyeu90
New Member

thanks lang moda

0 Karma
Get Updates on the Splunk Community!

Monitoring MariaDB and MySQL

In a previous post, we explored monitoring PostgreSQL and general best practices around which metrics to ...

Financial Services Industry Use Cases, ITSI Best Practices, and More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Splunk Federated Analytics for Amazon Security Lake

Thursday, November 21, 2024  |  11AM PT / 2PM ET Register Now Join our session to see the technical ...