Training + Certification Discussions

Has the sample data or the lab changed for Fundamentals 1?

Biggy
Explorer

The first time I noticed something might be different was during lab 5. There is a part of the lab that asks you to look at the source type and observe that the results from the query are coming from both the web_server and the web_application. This was not true, all the results came from the web_server. Now in lab 6 it asks me to run a query for index=main sourcetype=access_combined_wcookie action=purchase but no results are returned. I am sure that I will be able to get through the quiz but I am wondering if there is something that needs to be updated such as the data or the lab.

0 Karma
1 Solution

Biggy
Explorer

cbreshears,

The data was uploaded correctly. I honestly can't even imagine how an upload would be ingested incorrectly unless you edit the files that are provided by Splunk.

I figured out what was going on today... I noticed that each time a search is executed that the time is reset back to the 24 hour default. Everything appears to be returning results as intended now.

View solution in original post

0 Karma

Biggy
Explorer

cbreshears,

The data was uploaded correctly. I honestly can't even imagine how an upload would be ingested incorrectly unless you edit the files that are provided by Splunk.

I figured out what was going on today... I noticed that each time a search is executed that the time is reset back to the 24 hour default. Everything appears to be returning results as intended now.

0 Karma

woodcock
Esteemed Legend

@Biggy, you should click Accept to close the question.

0 Karma

DalJeanis
Legend

Yes, that would do it.

0 Karma

cbreshears_splu
Splunk Employee
Splunk Employee

Biggy, it sounds like you might have ingested the data incorrectly. Please send an email to elearn@splunk.com and we will help you troubleshoot.

0 Karma

DalJeanis
Legend

We've alerted that group to review and respond.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...