micro@lab:~/splunk-lab$ docker-compose exec splunk bash
/opt/splunk/etc/users/admin/search/history/226564ab2f07.csv
Here are the unique search queries from the provided data, one per line:
search source="tutorialdata (1).zip:*" index="sree"
search index="sree"
search index="sree"
| metadata type=sourcetypes | search totalCount > 0
search index="tutorial_data"
search index="tutorial_data"
search index="tutorial_data"
search index="tutorial_data" sourcetype="access_combined_wcookie"
search index="tutorial_data" sourcetype="access_combined_wcookie" host="www2"
search index="tutorial_data" sourcetype="access_*" host="www2"
| loadjob 1745507275.56 events=t ignore_running=f require_finished=f | search index=* OR index=_* sourcetype=access_combined_wcookie | head 1000
| metadata type=sourcetypes | search totalCount > 0
search index="tutorial_data" sourcetype="access_combined_wcookie"
| loadjob 1745508521.71 events=t ignore_running=f require_finished=f | search index=* OR index=_* sourcetype=access_combined_wcookie | head 1000
| loadjob 1745508521.71 events=t ignore_running=f require_finished=f | search index=* OR index=_* sourcetype=access_combined_wcookie | head 1000
| loadjob 1745508521.71 events=t ignore_running=f require_finished=f | search index=* OR index=_* sourcetype=access_combined_wcookie | rex field=_raw "(?ms)^(?P<MyIP>[^ ]+)" offset_field=_extracted_fields_bounds | head 1000
| metadata type=sourcetypes | search totalCount > 0
search index="tutorial_data" sourcetype="access_combined_wcookie"
search index="tutorial_data" sourcetype="access_combined_wcookie" Moz
search index="tutorial_data" sourcetype="access_combined_wcookie" chrome
search index="tutorial_data" sourcetype="access_combined_wcookie" moz
search index="tutorial_data" sourcetype="access_combined_wcookie" Mozilla
search index="tutorial_data" sourcetype="access_combined_wcookie" 200
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase|top clientip
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | table clientip
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table count
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip=87.194.216.51
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip=87.194.216.51
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | table clientip
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip=[search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip]
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip="[search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip]"
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase [search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip]
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip=[search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip]
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1 | rename clientip "VIP Customer"
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1 | table count
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip=87.194.216.51
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table count
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip=[search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip]
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip=[search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip]
search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase clientip="[search index="tutorial_data" sourcetype="access_combined_wcookie" status=200 action=purchase | top clientip limit=1| table clientip]"
These queries are derived from your provided CSV and represent the unique searches executed in Splunk.