The first time I noticed something might be different was during lab 5. There is a part of the lab that asks you to look at the source type and observe that the results from the query are coming from both the web_server and the web_application. This was not true, all the results came from the web_server. Now in lab 6 it asks me to run a query for index=main sourcetype=access_combined_wcookie action=purchase but no results are returned. I am sure that I will be able to get through the quiz but I am wondering if there is something that needs to be updated such as the data or the lab.
cbreshears,
The data was uploaded correctly. I honestly can't even imagine how an upload would be ingested incorrectly unless you edit the files that are provided by Splunk.
I figured out what was going on today... I noticed that each time a search is executed that the time is reset back to the 24 hour default. Everything appears to be returning results as intended now.
cbreshears,
The data was uploaded correctly. I honestly can't even imagine how an upload would be ingested incorrectly unless you edit the files that are provided by Splunk.
I figured out what was going on today... I noticed that each time a search is executed that the time is reset back to the 24 hour default. Everything appears to be returning results as intended now.
@Biggy, you should click Accept
to close the question.
Yes, that would do it.
Biggy, it sounds like you might have ingested the data incorrectly. Please send an email to elearn@splunk.com and we will help you troubleshoot.
We've alerted that group to review and respond.