SPLK-1002 Advanced Visualization and Lookups • Set 6
SPLK-1002 Advanced Visualization and Lookups Practice Test 6 — 15 questions with explanations. Free, no signup.
The security operations center (SOC) team at a medium-sized enterprise uses Splunk to investigate potential threats. They maintain a CSV lookup file named 'threat_intel.csv' that contains a list of known malicious IP addresses along with a threat score. The lookup is configured in transforms.conf as:
[threat_intel]filename = threat_intel.csv match_type = WILDCARD(ip)
They frequently run the following search to enrich firewall events with threat scores:
index=firewall sourcetype=firewall_logs | lookup threat_intel src_ip OUTPUT threat_score | where threat_score > 5
Recently, analysts noticed that some IP addresses known to be present in the lookup file are not being matched in search results. They have verified that the lookup file is correctly formatted and contains those IPs, and the transforms.conf has not been altered. They also confirmed that the events contain the field src_ip with the correct IP addresses. Which of the following is the most likely cause of the missing matches?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.