Getting Data In

Ingested data not fond

RB1
Observer

Hello,

I am doing the Splunk Fundamentals module 4 lab. After ingesting the data it's nowhere to be found. Please help.

Labels (1)
0 Karma

RB1
Observer

Please help

0 Karma

RB1
Observer

in the SplunkFundamentals1_module4 Steps 35 – 37 state that the “What to Search”  summary of indexed events will appear to the right when clicking the Search and Reporting App from the side bar to the left. The “What to Search” summary is not displayed. “Analyze Your Data with Table Views   New!” is shown where the  “What to Search” summary should be displayed. The next lab uses this same “What to Search” summary for it.

 

0 Karma

RB1
Observer

Logged in as Admin, the What to Search information is not displayed, nor is there a place to display any What to Search information.

Analyze Your Data with Table Views (New!) is displayed where the What to Search information should be displayed.

0 Karma

aasabatini
Motivator

Hi @RB1 

try to expand your timerange on your searchbar.

please check the inputs stanza to verify where are stored your data.

if didn't help please add more details

Regards

Alessandro

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

RB1
Observer

Expanding the search will help me find what I uploaded, but it does not appear when clicking the the Search and Reporting app sidebar. When I log in as a power user nothing appears when clicking the the Search and Reporting app sidebar. Nothing is found using the expanded search logged in as the power user.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!