Hi @brutha_analog, at first, it's always better to open a new question instead add to another one, in this way you limit your choices to have a quick and better answer. Then, using the Free license you have a full Splunk environment for 60 days with the only limit of indexing max 500 MB/day, but for testing it should be sufficient. If you need sources or testing, you can access (and I hint to do it) the Splunk Search Tutorial (https://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/WelcometotheSearchTutorial) that theaches you in searching and gives you the tutorial data. About line data, you can also use the os log from your machine. Ciao. Giuseppe
... View more