Training + Certification Discussions

Splunk Fundamentals 1 Lab 5 In the search bar, type the search: error OR fail*

swoopteam
New Member

In the Splunk Fundamentals 1 class Lab 5 it states "In the search bar, type the search: error OR fail* ". I have the time set to All Time
The search is supposed to show hosts, login errors or fails. Mine shows 0 events.
I don't see in Lab 4 any instructions to load data into splunk. How do I get the search to report real events and/or how do I load lab 4 data into splunk so I can find it in lab 5? Thank you.

Tags (2)
0 Karma

broberg
Communicator

Do you have any events at all? Did you import all the data from the lab 4?
Follow the lab 4 instructions and make sure you get all events you need.
You download a zip-file and ingest data into splunk.

0 Karma

swoopteam
New Member

No events at all. I had been watching the training video and not reading manual. I read the manual and after reviewing pages very carefully found the phrase access.log was in the little area showing how to up load a file. I tried that and it uploaded the file. Haven't searched yet. Will try tomorrow. Thank yo for your help.

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...