A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)
This is a tricky one, but I think B and D are the culprits. The missing network tag and not using the field directly are probably the reasons the colleague can't see it.
D is definitely the issue here. If the colleague didn't explicitly use the field, it won't show up in the search results, even if it's there. Fast Mode makes that even more likely.
Cathrine
2 months agoJannette
30 days agoCarey
1 months agoPhyliss
1 months agoGeoffrey
3 months agoVelda
27 days agoJustine
29 days agoMelissa
30 days agoPaulene
1 months agoVince
1 months agoRonnie
1 months agoTijuana
1 months agoAudry
2 months agoCecil
3 months agoCasie
2 months agoHermila
3 months agoTonette
3 months agoRoselle
3 months agoMatthew
3 months agoKayleigh
4 months ago