exam questions

Exam SPLK-2002 All Questions

View all questions & answers for the SPLK-2002 exam

Exam SPLK-2002 topic 1 question 73 discussion

Actual exam question from Splunk's SPLK-2002
Question #: 73
Topic #: 1
[All SPLK-2002 Questions]

A Splunk user successfully extracted an ip address into a field called src_ip. Their colleague cannot see that field in their search results with events known to have src_ip. Which of the following may explain the problem? (Select all that apply.)

  • A. The field was extracted as a private knowledge object.
  • B. The events are tagged as communicate, but are missing the network tag.
  • C. The Typing Queue, which does regular expression replacements, is blocked.
  • D. The colleague did not explicitly use the field in the search and the search was set to Fast Mode.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Reference:
https://answers.splunk.com/answers/657187/map-command-field-not-being-evaluated.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sadhka
Highly Voted 4 years, 5 months ago
A and D
upvoted 11 times
...
manu78
Highly Voted 3 years, 10 months ago
A and D are correct
upvoted 5 times
...
580ce47
Most Recent 3 weeks, 3 days ago
Selected Answer: A
A is correct more likely maybe D but if I had to choose one it would be A
upvoted 1 times
...
CactiAZ
4 months ago
It's A and D
upvoted 1 times
...
wirix25718
1 year, 10 months ago
page 101 troubleshooting
upvoted 1 times
...
KiranVM
1 year, 11 months ago
Could be A and D
upvoted 1 times
...
minombrerodrigo
2 years, 1 month ago
Selected Answer: A
A and D is correct
upvoted 1 times
...
Redtonyeah
2 years, 11 months ago
A and D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago