<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where can I get the updated sample data for practicing searches using SPL? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625564#M107515</link>
    <description>&lt;P&gt;You'll need to fix the filesystem on which the botsv3 index is stored.&amp;nbsp; Perhaps it's in read-only mode or maybe the permissions on the botsv3 directory are incorrect.&lt;/P&gt;</description>
    <pubDate>Sat, 31 Dec 2022 13:37:18 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-12-31T13:37:18Z</dc:date>
    <item>
      <title>Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/624760#M107390</link>
      <description>&lt;P&gt;please where can i get the updated sample data for practicing searches using SPL? thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 20:17:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/624760#M107390</guid>
      <dc:creator>Lorenzo1</dc:creator>
      <dc:date>2022-12-19T20:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/624768#M107392</link>
      <description>&lt;P&gt;You can get sample data literally anywhere.&amp;nbsp; Any data can be used to practice searching.&amp;nbsp; Your own workstation probably is the best place to start.&amp;nbsp; If you want more variety in your data, download the BOTS3 (Boss Of The SOC version3) dataset at&amp;nbsp;&lt;A href="https://github.com/splunk/botsv3" target="_blank" rel="noopener"&gt;https://github.com/splunk/botsv3&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 21:46:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/624768#M107392</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-19T21:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/624806#M107397</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/247690"&gt;@Lorenzo1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you can use the hint of&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;or see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/SearchTutorial/Systemrequirements#Download_the_tutorial_data_files" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.3/SearchTutorial/Systemrequirements#Download_the_tutorial_data_files&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 08:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/624806#M107397</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-12-20T08:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625288#M107468</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;thanxx bro i seen it in v3.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 02:48:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625288#M107468</guid>
      <dc:creator>Lorenzo1</dc:creator>
      <dc:date>2022-12-27T02:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625289#M107469</link>
      <description>&lt;P&gt;hey bro do i need to download and install all the app/add -on before installing the BOTS v3? Cos i decided not to download the ones that had to do with microsoft and windows since am using Mac.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 03:32:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625289#M107469</guid>
      <dc:creator>Lorenzo1</dc:creator>
      <dc:date>2022-12-27T03:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625292#M107470</link>
      <description>&lt;P&gt;also i tried to scp the .tgz file from my local folder to the virtual server so i can untar and install it there but was getting "permission denied" error (screenshot attached). can you help pls.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 06:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625292#M107470</guid>
      <dc:creator>Lorenzo1</dc:creator>
      <dc:date>2022-12-27T06:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625316#M107475</link>
      <description>&lt;P&gt;It's out of scope of this forum I'm afraid. It's not that I don't want to help you out here but you obviously have problems with most basic unix CLI operations so it's better that you train somewhere else than if I give you a copy-paste solution which you can mistype and break your whole installation.&lt;/P&gt;&lt;P&gt;Find some basic unix/linux CLI tutorial and start from there.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 09:48:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625316#M107475</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-12-27T09:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625440#M107497</link>
      <description>&lt;P&gt;i dont understand . i already have a good hand in linux. If i could deploy a fully clustered splunk environment then i dont think i need basic linux training. But its ok if you say so. thanxx.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 23:54:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625440#M107497</guid>
      <dc:creator>Lorenzo1</dc:creator>
      <dc:date>2022-12-28T23:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625442#M107498</link>
      <description>&lt;P&gt;Use &lt;FONT face="courier new,courier"&gt;chmod&lt;/FONT&gt; to set the permissions.&lt;/P&gt;&lt;P&gt;You do not need any apps or add-ons to use the BOTS data set.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 00:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625442#M107498</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-29T00:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625447#M107499</link>
      <description>&lt;P&gt;Sorry, mate, but it seems so.&lt;/P&gt;&lt;P&gt;From the screenshots you provided it seems that you're trying to "run" your home directory and your scp syntax is wrong (use man scp to read about it). It's not an insult. It's just pointing out that you're missing the basics.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 07:14:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625447#M107499</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-12-29T07:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625555#M107510</link>
      <description>&lt;P&gt;ok lemme try that. Thanks for your time.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 21:29:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625555#M107510</guid>
      <dc:creator>Lorenzo1</dc:creator>
      <dc:date>2022-12-30T21:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625559#M107512</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;so i was able to install botsv3 but got this error after restarting and splunkd stopped running. pls how can i solve this cos i can see am almost there. thanxx.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;homePath='/opt/splunk/etc/apps/botsv3_data_set/var/lib/splunk/botsv3/db' of index=botsv3 on unusable filesystem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Validating databases (splunkd validatedb) failed with code '1'&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;attached is the screenshot,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 08:07:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625559#M107512</guid>
      <dc:creator>Lorenzo1</dc:creator>
      <dc:date>2022-12-31T08:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Where can I get the updated sample data for practicing searches using SPL?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625564#M107515</link>
      <description>&lt;P&gt;You'll need to fix the filesystem on which the botsv3 index is stored.&amp;nbsp; Perhaps it's in read-only mode or maybe the permissions on the botsv3 directory are incorrect.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Dec 2022 13:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-can-I-get-the-updated-sample-data-for-practicing-searches/m-p/625564#M107515</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-31T13:37:18Z</dc:date>
    </item>
  </channel>
</rss>

