Splunk Search

How to view a list of my most recent searches (search history)

mfrost8
Builder

This seems like it should be an easy question, but I haven't found the answer....

I ran a search recently and it had a lot of stuff in it but I never saved it. It wasn't something I thought I'd need to refer to later so that was no point in saving. I'm hoping it's still in my search history somewhere, but the only way I've ever interacted with my search history is when I've typed the first part of a search I've run before.

Is there some way to just tell Splunk to show me all the searches it's seen me run so I can find the one I'm looking for?

Thanks

Tags (1)
1 Solution

rdownie
Communicator

try the history command.


|history | head 20

or however many you want to see.

View solution in original post

rdownie
Communicator

try the history command.


|history | head 20

or however many you want to see.

mfrost8
Builder

Thanks very much, rdownie!

0 Karma

yeuyeu90
New Member

thanks lang moda

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...