Why is it that neither of the Splunk.com site dashboard examples return data for the following
query: index=main sourcetype=access_combined* status=200 action=purchase |timechart count by productid ?
Here's what the videos say we should get:
But here's what the query returns:
It groups by date successfully, but doesn't yield results by product.
Both of the online dashboard creation videos in the url below yield the desired results shown in the first screenshot above. Note: the source="tutorialdata.zip:*".
Two video training sites are here:
https://www.splunk.com/en_us/training/videos/all-videos.html
https://www.splunk.com/en_us/blog/learn/splunk-tutorials.html#education
Field names are case sensitive - try using productId rather than productid
Can you share some of the events you have?
Sure, and thanks for asking.
The data file is called "tutorialdata.zip", and was downloaded from the Splunk site here:
Thanks again.
Avery
Field names are case sensitive - try using productId rather than productid
That was it! Thanks for solving!