Hello,
I am doing the Splunk Fundamentals module 4 lab. After ingesting the data it's nowhere to be found. Please help.
Please help
in the SplunkFundamentals1_module4 Steps 35 – 37 state that the “What to Search” summary of indexed events will appear to the right when clicking the Search and Reporting App from the side bar to the left. The “What to Search” summary is not displayed. “Analyze Your Data with Table Views New!” is shown where the “What to Search” summary should be displayed. The next lab uses this same “What to Search” summary for it.
Logged in as Admin, the What to Search information is not displayed, nor is there a place to display any What to Search information.
Analyze Your Data with Table Views (New!) is displayed where the What to Search information should be displayed.
Hi @RB1
try to expand your timerange on your searchbar.
please check the inputs stanza to verify where are stored your data.
if didn't help please add more details
Regards
Alessandro
Expanding the search will help me find what I uploaded, but it does not appear when clicking the the Search and Reporting app sidebar. When I log in as a power user nothing appears when clicking the the Search and Reporting app sidebar. Nothing is found using the expanded search logged in as the power user.