Installation

[devtutorial] - Cannot setup sample data bundle?

jakegoodman01
New Member

Hi,

I am trying to use Splunk for the first time and I am not able to complete the devtutorial.

I successfully created an app called "Dev Tutorial" (instructions). 

Then I followed these instructions and setup an index called "devtutorial" (which I enabled), installed the "Eventgen" app (which appears in my app directory as "SA-Eventgen"), navigated to "Settings >> Data Inputs >> Eventgen" and enabled the "modinput_eventgen" source type, downloaded sample_bundle and changed the index to "devtutorial", I refeshed Splunk by using this link: http://localhost:8000/debug/refresh.

But, when I go to my "Dev Tutorial" app and search for "index="devtutorial" ", no events show up. Also when I go to the "SA-Eventgen" app itself, I get no data:

Screen Shot 2022-08-11 at 6.21.06 PM.png

 

Can I get some help with this please?

Labels (5)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...