Hello Spluksters,
I installed the Splunk enterprise. I am also reading the free Splunk e-book. Chapter 2 talks of installing some practice data and gives steps that don't arrive me to desired goal.
Would you troubleshoot this ASAP?
Thanks,
Allan
Logged into my admin Splunk Enterprise. Clicked on "Add Data" that prompted another click to "upload files from my computer". Next was to click "Select File", located the "tutorialdata" from my computer. Followed the remaining tutorial steps and guess what I ghat all the buttercup machine data for practice.
Plan to take the Splunk user exam Saturday!
Good work! Uploading data directly into Splunk is a good start, once you get more of an understanding, you should try uploading data on a remote server into Splunk using a universal forwarder.
Also, please accept/upvote any helpful answers
At least post URL to download the ebook. Better yet, post the steps. Help us to help you.
Got Splunked!
You need to either forward the data into Splunk from a remote host or you can upload it directly into Splunk. Go to Settings>Data Inputs
and upload your data.. make sure to go through all the steps and your data is in Splunk. Make sure your searching the right index, if you didnt specify an index then it will go into the main index. To look, you could also run this search
| metasearch index=*
This will return data, look on the left hand side and look for the field called index
and click it. See what index the data is in then go to the search and type in index=<INDEX-NAME>
Happily splunked!
@LionKing18, follow Splunk Tutorial Dcumentation to install Splunk and add tutorial data. If something is not working as expected, please add details on step not working and any issue/error that you see.
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/Systemrequirements
Validate that events are showing up in the index that you have created and perform a search by All Time if required.
Got splunked!
@LionKing18, if the answer helped please accept the same. Also up vote the comments that helped! All the Best!