I am using Splunk Enterprise for the first time. I added data following the steps in the online tutorial. But.. in the tutorial when they go to search the data it comes right up. I added a server.. and I am not getting any data.
What step am I missing?
What is the time range that you selected when running the search? The timestamp on the events in the logs of tutorialdata.zip will be of before you downloaded it, so make sure your time range include that. E.g. If you've downloaded the data today, try last 24hs or last 7 days.
Start by going to search and just putting in this command
index=* | head 5
what did you get?