In the Splunk Fundamentals 1 class Lab 5 it states "In the search bar, type the search: error OR fail* ". I have the time set to All Time
The search is supposed to show hosts, login errors or fails. Mine shows 0 events.
I don't see in Lab 4 any instructions to load data into splunk. How do I get the search to report real events and/or how do I load lab 4 data into splunk so I can find it in lab 5? Thank you.
↧