Getting Data In

Splunk Fundamental Module 4 Lab

supyaetun
New Member

After uploading the 3 files as per the instructions, I am supposed to see my events but there is nothing on the page even when I am logged in as admin or power user. 

Labels (1)
Tags (2)
0 Karma

etmaurer
Observer

Same here...uploaded 3 files into Splunk w/o issue but they don't appear as having been so as nothing to search upon.  Expanded data to "all time" as well.

Ed in Tampa

 

0 Karma

etmaurer
Observer

Ok, found an email address to Splunk Education team (elearn@splunk.com) ...and submitted my question; here is the response:

"Hello Ed,

You may proceed to the next module/lab. The information indicating the number of events to indexed does not appear on this page in this version of Splunk.

Mike Halladay

IOD Technical Support Engineer"

I have since been able to perform a search & find data from these 3 lab files.  BTW, I'm running the Windows version on my desktop.

Hope this helps somebody, I could have used this guidance last week.

Ed in Tampa

 

0 Karma

aasabatini
Motivator

Hi,

 

try to expand your timerange and if you don't specify the index name splunk automatically puts your data on the index=main.

 

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Get Updates on the Splunk Community!

Data Preparation Made Easy: SPL2 for Edge Processor

By now, you may have heard the exciting news that Edge Processor, the easy-to-use Splunk data preparation tool ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Tips & Tricks When Using Ingest Actions

Tune in to learn about:Large scale architecture when using Ingest ActionsRegEx performance considerations ...