Getting Data In

Why is uploaded data missing?

suvi1611
New Member

Hi,

I am new to splunk and trying to upload data for practising. I amd using the data from the the below link.

https://docs.splunk.com/Documentation/Splunk/9.0.5/SearchTutorial/GetthetutorialdataintoSplunk

When I try to upload the tutorialdata.zip, It loads for a long time and I get a read timeout

When I extract the tutorialdata.zip and upload a single log file . No issues in uploading, It uploads the logs file and when I click Next --> Set Source Type is empty and not displaying the raw data (as shown in the screenshot) and If I continue till the end, submit and  search for the index/source, I get 0 events found.

Could you please suggest If I am missing anything. I am currently using a free license option. 

 

suvi1611_0-1687181697433.png

suvi1611_1-1687181798323.png

 

 

Labels (1)
0 Karma

suvi1611
New Member

Thank you for the quick update. I just tried in Splunk cloud with the same zip file and it was working as expected.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

at least earlier this has worked exactly how the manual told. If it didn’t work, then you should try to use trial or full enterprise version, not a free version. The free version has some limitations which shouldn’t affect for this test, but it’s the difference for working environment.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...