Skip to main content
ko_history app icon

ko_history

Versions Splunk knowledge objects via summary indexing, enabling administrators to audit changes and recover dashboards, alerts, reports, and configuration objects after accidental deletion or modification.Built by Jørn Lyder Hansen
splunk product badge

Default Version 1.3.0

September 14, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

KO History captures and versions Splunk knowledge objects through summary indexing, providing administrators with an audit trail and recovery mechanism for dashboards, saved searches, alerts, macros, event types, field extractions, lookups, and tags. The app periodically snapshots these objects into a dedicated summary index, preserving complete source code, authorship, and timestamps. When a knowledge object is accidentally deleted, overwritten, or moved, administrators can search the version history, compare changes through inline visual diffs, and optionally restore previous versions. The app includes custom visualizations for side-by-side source comparison and dashboard preview rendering. Restore functionality is opt-in and disabled by default, with one-click restore supported for dashboards and saved searches. All versioning and audit data persists independently in the ko_history index, ensuring recovery remains possible even after the original object has been removed from the system.