A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
This is a tricky one, but I think B and D are the culprits. The missing network tag and not using the field directly are probably the reasons the colleague can't see it.
D is definitely the issue here. If the colleague didn't explicitly use the field, it won't show up in the search results, even if it's there. Fast Mode makes that even more likely.
Cathrine
1 months agoPhyliss
4 days agoGeoffrey
2 months agoPaulene
5 hours agoVince
1 days agoRonnie
3 days agoTijuana
4 days agoAudry
1 months agoCecil
2 months agoCasie
1 months agoHermila
1 months agoTonette
2 months agoRoselle
2 months agoMatthew
2 months agoKayleigh
3 months ago