Splunk® Enterprise

Search Manual

Acrobat logo Download manual as PDF

Splunk Enterprise version 6.x is no longer supported as of October 23, 2019. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Acrobat logo Download topic as PDF

Search history

Your search history appears in both the Search Summary view and the New Search view. In the Search Summary view, the history appears at the bottom of the view in the Search History panel. In the New Search view, the history appears as part of the Search Assistant.

In the Search Summary view, use the Search History panel to view and interact with the searches that you have run previously.

  1. To view the Search History panel, click Search in the Apps bar. The Search Summary view opens, which is the landing page for Splunk Search.
  2. Under Search History, click Expand your search history to view your search history. Your search history displays as a table with the following columns:
  • Search: Contains the search string, displayed as plain text so that you can copy the contents. By default, the Search History table truncates the search string to fit on a single line. For longer search strings, you can click the expand icon to the left of the search string to display the full search string.
  • Actions: Contains the action, Add to search. Click Add to Search to replace the contents of the search bar with the selected historical search contents. Command-click Add to Search to open the search in a new tab.
  • Last Run: Contains the date and time when the search was last run.

You can interact with your Search History in the following ways:

  • Filter with keywords: Use the filter bar to run keyword searches against the text of your historical searches.
  • Filter by time: Select from the list of time filters based on when the search was written and last run. You can display the search history with No Time Filter or select from a list of predefined time filters: Today, Last 7 Days, and Last 30 Days.
  • Sort table contents: Click the column headers for Search or Last Run to sort the table results.

See Also

Navigating Splunk Web

Last modified on 12 April, 2017
Search modes
Search command primer

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.4.10, 6.4.11, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.5.7, 6.5.8, 6.5.9, 6.5.10

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters