Splunk® Enterprise

Search Tutorial

Splunk Enterprise version 9.0 will no longer be supported as of June 14, 2024. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.

Upload the tutorial data

This tutorial uses a set of data that is designed to show you the features in the product. Using the tutorial data ensures that your search results are consistent with the steps in the tutorial.


  • You must have the tutorial data files on your computer.
  • The tutorialdata.zip file must remain compressed to upload the file successfully. Some browsers automatically uncompress ZIP files. See Download the tutorial data files for more information.
  • It is helpful to understand the type of data you that are uploading with this tutorial. See What is in the tutorial data?.

Use the Add Data wizard

  1. If there is a Welcome window displayed, close that window.
  2. Click Settings > Add Data.
    This screen image shows the Add Data icon in the Settings window.

  3. At the bottom of the window, click Upload. There are other options for adding data, but for this tutorial you will upload the data files.
    This screen image shows the Upload icon on the screen. The Upload icon is in the section "Or get data in with the following methods".

  4. Under Select Source, click Select File.
    This screen image shows the first step in adding data, Select Source.  The Select File button is highlighted. Browse to where you downloaded the tutorialdata.zip file.

  5. In your download directory, select the tutorialdata.zip file and click Open.

    Because you specified a compressed file, the Splunk software recognizes that type of data source. The Set Source Type step in the Add Data wizard is skipped. When you load data that is not in a compressed file, you will be asked to set the data source type.

  6. Click Next to continue to Input Settings.

  7. Under Input Settings, you can override the default settings for Host, Source type, and Index.
    Because this tutorial uses a ZIP file, you are going to modify the Host setting to assign the host values by using a portion of the path name for the files included in the ZIP file. The setting that you specify depends whether you are using Splunk Cloud Platform or Splunk Enterprise, and on the operating system that you are using.

    Splunk Cloud Platform
    a. Select Segment in path.
    b. Type 1 for the segment number.
    Splunk Enterprise for Linux or Mac OS X
    a. Select Segment in path.
    b. Type 1 for the segment number.
    This screen image shows the next step in adding data, Input Settings The Segment in path option is highlighted.
    Splunk Enterprise for Windows
    a. Select Regular expression on path.
    b. Type \\(.*)\/ for the regex to extract the host values from the path.
    This screen image shows the next step in adding data, Input Settings The Regular expression on path option is selected and the regular expression is typed into the field.
  8. Click Review. The following screen appears where you can review your input settings.
    This screen image shows the next step in adding data, Review. The name of the file that you are uploading and the host setting are displayed.

  9. Click Submit to add the data.
    This screen image shows the last step in adding data. The screen shows the file was uploaded successfully. The screen shows the options for what you can do next.

  10.  To see the data in the Search app, click Start Searching.
    You might see a screen asking if you want to take a tour. You can take the tour or click Skip.
    The Search app opens and a search is automatically run on the tutorial data source.
    This screen image shows that a simple search was run to find all of the tutorial data. The data now appears as events in the bottom half of the window.

    Success! The results confirm that the data in the tutorialdata.zip file was indexed and that events were created.
  11.  Click the Splunk logo to return to Splunk Home.

Next step

You have completed Part 2 of the Search Tutorial.

Now you know how to add data to your Splunk platform. Next, you will begin to learn how to search that data. Continue to Part 3: Using the Splunk Search App.

Last modified on 06 September, 2023
What is in the tutorial data?   Exploring the Search views

This documentation applies to the following versions of Splunk® Enterprise: 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.2.0, 9.2.1, 9.2.2

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters