<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to get botsv1 in search result in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672790#M230411</link>
    <description>If I recall right, there is no need to do anything special, just follow the instructions.&lt;BR /&gt;Another option is use this &lt;A href="https://bots.splunk.com/login?redirect=/" target="_blank"&gt;https://bots.splunk.com/login?redirect=/&lt;/A&gt;&lt;BR /&gt;</description>
    <pubDate>Wed, 27 Dec 2023 20:17:28 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-12-27T20:17:28Z</dc:date>
    <item>
      <title>Unable to get botsv1 in search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672722#M230380</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a botsv1 dataset uploaded in Splunk simulated environment. But when I search "index=botsv1" , it returns 0 events. Although I have seen the dataset in apps folder. Also it can be seen in indexes in settings section. Nothing&amp;nbsp; can be searched using keyword botsv1.&lt;/P&gt;&lt;P&gt;I have tried various search options, but all failed. Please help me.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 10:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672722#M230380</guid>
      <dc:creator>Dipti</dc:creator>
      <dc:date>2023-12-27T10:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get botsv1 in search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672724#M230381</link>
      <description>With those old datasets you must use "earliest=1" for all searches or "All time" option.</description>
      <pubDate>Wed, 27 Dec 2023 10:08:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672724#M230381</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-12-27T10:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get botsv1 in search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672787#M230408</link>
      <description>&lt;P&gt;Thanks for the reply. I tried the above but its still showing 0 events. I searched "index=botsv1 earliest=1" and also only index="botsv1" but no events. I am all stuck.&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 19:55:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672787#M230408</guid>
      <dc:creator>Dipti</dc:creator>
      <dc:date>2023-12-27T19:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get botsv1 in search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672788#M230409</link>
      <description>&lt;P&gt;Do I need to run any command in terminal to activate the dataset. or anything else.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Dec 2023 19:56:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672788#M230409</guid>
      <dc:creator>Dipti</dc:creator>
      <dc:date>2023-12-27T19:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get botsv1 in search result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672790#M230411</link>
      <description>If I recall right, there is no need to do anything special, just follow the instructions.&lt;BR /&gt;Another option is use this &lt;A href="https://bots.splunk.com/login?redirect=/" target="_blank"&gt;https://bots.splunk.com/login?redirect=/&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Dec 2023 20:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-get-botsv1-in-search-result/m-p/672790#M230411</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-12-27T20:17:28Z</dc:date>
    </item>
  </channel>
</rss>

