Scarily enough, it appears to be enabled by default. At least with 9.3.1, this feature is not enabled by default: search_history_storage_mode = <string>
* The storage mode by which a search head cluster saves search history.
* Valid storage modes include "csv" and "kvstore".
[...]
* Default: csv https://docs.splunk.com/Documentation/Splunk/9.3.1/Admin/Limitsconf#History
... View more