QuestionQ66
Search ProblemsA Splunk user successfully extracted an IP address into a field named src_ip. Their colleague cannot see that field in search results for events known to contain src_ip. Which of the following could explain this issue? (Select all that apply.)
Choose two
- A The field was extracted as a private knowledge object.
- B The events are tagged as communicate, but are missing the network tag.
- C The Typing Queue, which does regular expression replacements, is blocked.
- D The colleague did not explicitly use the field in the search and the search was set to Fast Mode.
Community Discussion