Hi,
I have a botsv1 dataset uploaded in Splunk simulated environment. But when I search "index=botsv1" , it returns 0 events. Although I have seen the dataset in apps folder. Also it can be seen in indexes in settings section. Nothing can be searched using keyword botsv1.
I have tried various search options, but all failed. Please help me.
Thanks in advance.
Thanks for the reply. I tried the above but its still showing 0 events. I searched "index=botsv1 earliest=1" and also only index="botsv1" but no events. I am all stuck.
Thanks again.
Do I need to run any command in terminal to activate the dataset. or anything else.
Thanks