A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
This is a tricky one, but I think B and D are the culprits. The missing network tag and not using the field directly are probably the reasons the colleague can't see it.
D is definitely the issue here. If the colleague didn't explicitly use the field, it won't show up in the search results, even if it's there. Fast Mode makes that even more likely.
Geoffrey
5 days agoCecil
8 days agoTonette
12 days agoRoselle
16 days agoMatthew
18 days agoKayleigh
25 days ago