Splunk Dev

No search history for clean install of 8.01 Enterprise

dkozinn
Path Finder

I have a fresh install of Splunk Enterprise 8.01 on a box running Ubuntu 19.10 as a standalone instance (no clustering, etc.) When I access the Search app, there is never any history showing under Search History. Using |history as a search does not product any output either. If I look in /opt/splunk/etc/users/myuser/search/history there is a CSV file that gets updated with each search I enter. If I look at the _audit index, I do see the searches there.

I've looked through a few other posts here but none seems relevant. Any suggestions?

0 Karma

dkozinn
Path Finder

Trying to bump for visibility. Still happens after upgrading to 8.0.3.

The only thing I noticed that might be unusual (and I don't know if it is) is that the permissions on the CSV file are that it's set to 0600 and owned by root. The directory itself and the only other file there (called .dummy_history) are all owned by splunk:splunk. If I change the ownership of the .csv to be splunk:splunk it changes back to root.

0 Karma
Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...