This seems like it should be an easy question, but I haven't found the answer....
I ran a search recently and it had a lot of stuff in it but I never saved it. It wasn't something I thought I'd need to refer to later so that was no point in saving. I'm hoping it's still in my search history somewhere, but the only way I've ever interacted with my search history is when I've typed the first part of a search I've run before.
Is there some way to just tell Splunk to show me all the searches it's seen me run so I can find the one I'm looking for?
Thanks
try the history command.
|history | head 20
or however many you want to see.
try the history command.
|history | head 20
or however many you want to see.
Thanks very much, rdownie!
thanks lang moda