Splunk Search

Unable to get botsv1 in search result

Dipti
Explorer

Hi,

I have a botsv1 dataset uploaded in Splunk simulated environment. But when I search "index=botsv1" , it returns 0 events. Although I have seen the dataset in apps folder. Also it can be seen in indexes in settings section. Nothing  can be searched using keyword botsv1.

I have tried various search options, but all failed. Please help me.

Thanks in advance.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
With those old datasets you must use "earliest=1" for all searches or "All time" option.

Dipti
Explorer

Thanks for the reply. I tried the above but its still showing 0 events. I searched "index=botsv1 earliest=1" and also only index="botsv1" but no events. I am all stuck.

Thanks again.

0 Karma

Dipti
Explorer

Do I need to run any command in terminal to activate the dataset. or anything else.

Thanks 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
If I recall right, there is no need to do anything special, just follow the instructions.
Another option is use this https://bots.splunk.com/login?redirect=/
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...