A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
This is a tricky one, but I think B and D are the culprits. The missing network tag and not using the field directly are probably the reasons the colleague can't see it.
D is definitely the issue here. If the colleague didn't explicitly use the field, it won't show up in the search results, even if it's there. Fast Mode makes that even more likely.
Cathrine
27 days agoGeoffrey
1 months agoAudry
20 days agoCecil
1 months agoCasie
23 days agoHermila
29 days agoTonette
2 months agoRoselle
2 months agoMatthew
2 months agoKayleigh
2 months ago