Splunk Search

Unable to get botsv1 in search result

Dipti
Explorer

Hi,

I have a botsv1 dataset uploaded in Splunk simulated environment. But when I search "index=botsv1" , it returns 0 events. Although I have seen the dataset in apps folder. Also it can be seen in indexes in settings section. Nothing  can be searched using keyword botsv1.

I have tried various search options, but all failed. Please help me.

Thanks in advance.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
With those old datasets you must use "earliest=1" for all searches or "All time" option.

Dipti
Explorer

Thanks for the reply. I tried the above but its still showing 0 events. I searched "index=botsv1 earliest=1" and also only index="botsv1" but no events. I am all stuck.

Thanks again.

0 Karma

Dipti
Explorer

Do I need to run any command in terminal to activate the dataset. or anything else.

Thanks 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
If I recall right, there is no need to do anything special, just follow the instructions.
Another option is use this https://bots.splunk.com/login?redirect=/
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...