New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Splunk Enterprise Certified Architect SPLK-2002 Question # 2 Topic 1 Discussion

Splunk Enterprise Certified Architect SPLK-2002 Question # 2 Topic 1 Discussion

SPLK-2002 Exam Topic 1 Question 2 Discussion:
Question #: 2
Topic #: 1

A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)


A.

The field was extracted as a private knowledge object.


B.

The events are tagged as communicate, but are missing the network tag.


C.

The Typing Queue, which does regular expression replacements, is blocked.


D.

The colleague did not explicitly use the field in the search and the search was set to Fast Mode.


Get Premium SPLK-2002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.