User Manual

 


Search History

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.

Search History

As you search your Splunk Server, it logs a history of each of your searches in a separate index. To see your search history, type this search into the Splunk box:


index::history

Search History


The history index is a chronological list of all searches, each indexed as a separate event. For convenience search interface adds an extra link, Run this Splunk again, next to each event.


Splunk Professional includes the username associated with each search, too. You can search for a specific user's searches like this:


index::history user::joeuser

This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.


You must be logged into splunk.com in order to post comments. Log in now.

Was this documentation topic helpful?

If you'd like to hear back from us, please provide your email address:

We'd love to hear what you think about this topic or the documentation as a whole. Feedback you enter here will be delivered to the documentation team.