Training + Certification Discussions

Has anyone notice the typo's in the new 7 fundamentals book?

svalerga2
New Member

This is keeping people from moving forward when doing the scenarios from the manual. Starting in module 8.
_wcookie is missing. And so is the " " around ProductID.

0 Karma
1 Solution

cbreshears_splu
Splunk Employee
Splunk Employee

Material slides are for demonstration purposes only and do not match data provided for labs. Please use the lab module documents when working with lab server(s).

View solution in original post

cbreshears_splu
Splunk Employee
Splunk Employee

Material slides are for demonstration purposes only and do not match data provided for labs. Please use the lab module documents when working with lab server(s).

cbreshears_splu
Splunk Employee
Splunk Employee

Hello, which course are you taking? We are not seeing this issue with the Fundamentals Pt1 eLearning course (the course that uses the _wcookie sourcetype). Please contact us at elearn@splunk.com so that we can help troubleshoot.

0 Karma

svalerga2
New Member

So I am taking the User (Fundamentals 1) and doing the scenario's on page 103. This is on my local machine and is for testing purposes. Without the _wcookie in the sourcetype I was getting no results. After adding it I was able to finish pg.105. On the following when indexing security. I got no results. I had to use index=main. Also in the the dedup. This is the only thing that would work; index=main sourcetype="vendor_sales/vendor_sales" vendorid=*. But could not get table to work.
I am beginning to think I am missing something somewhere? Should I be using the cloud for the Fundamentals 1& 2? I want to pass mu User certification .

0 Karma

cbreshears_splu
Splunk Employee
Splunk Employee

It sounds like you are doing the scenarios from the course materials slides on the lab server. The material slides are for demonstration purposes only and do not match all data provided for labs. Please use the lab module documents when working with the lab server(s).

0 Karma

svalerga2
New Member

Lab Modules work fine. Its when I am doing scenarios in the main PDf with my name on it. I guess that is better suited for a real environment with indexers.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...