Splunk Search

Unable to get botsv1 in search result

Dipti
Explorer

Hi,

I have a botsv1 dataset uploaded in Splunk simulated environment. But when I search "index=botsv1" , it returns 0 events. Although I have seen the dataset in apps folder. Also it can be seen in indexes in settings section. Nothing  can be searched using keyword botsv1.

I have tried various search options, but all failed. Please help me.

Thanks in advance.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
With those old datasets you must use "earliest=1" for all searches or "All time" option.

Dipti
Explorer

Thanks for the reply. I tried the above but its still showing 0 events. I searched "index=botsv1 earliest=1" and also only index="botsv1" but no events. I am all stuck.

Thanks again.

0 Karma

Dipti
Explorer

Do I need to run any command in terminal to activate the dataset. or anything else.

Thanks 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
If I recall right, there is no need to do anything special, just follow the instructions.
Another option is use this https://bots.splunk.com/login?redirect=/
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...