Getting Data In

Splunk Fundamentals 1 - Lab 4 - Datas not found after indexation

Darkpat60
New Member

Hello,

I follow the Splunk Fundamentals 1 and have installed Splunk 8.2.1 as a local instance (Windows 10). The lab 4 material is composed of 3 files that have to be uploaded on splunk in an admin session. I follow the instructions and that seems to be working ok, but I don't see the indexed datas neither on the admin or power session after.

I tried to change the time span of the search results, to search in my datasets (empty in both sessions), nothing appears. I reuploaded the material and while saving a cvs file it seems the file was already there (from the first upload). But again, no results and no datas appear to have been indexed/ingested into splunk after.

Has anyone any idea to fix that or ever encountered this problem? Thanks a lot folks!

Labels (1)
0 Karma

Darkpat60
New Member

Ok sorry to spam, I kind of found the datas, they appear by clicking the "create a table view" and selecting the right index.But It seems that the datas is kind of processed this way, anyway the indexations was working.

So I made a search with an sample IP from the logs and had results with the searchbar. So ok datas are there (even if I don't have a view of the sources and other stats on the logs). Anyway, hope it helps, as the version seems to have changed since the version of fundamentals 1 materials.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...