SPLK-1003 • Practice Test 13
Free SPLK-1003 practice test — 15 questions with explanations. Set 13. No signup required.
A security analyst needs to enrich authentication logs with employee department information stored in a CSV file called 'employees.csv'. The CSV has fields: 'emp_id', 'name', 'department'. The authentication logs contain a field 'user_id' that matches 'emp_id'. Which search correctly enriches the events with the department field?