SPLK-1001 Using Fields and Lookups • Set 10
SPLK-1001 Using Fields and Lookups Practice Test 10 — 15 questions with explanations. Free, no signup.
A Splunk admin configured a CSV-based lookup to map device IP addresses to location data. The lookup 'devices.csv' has columns 'ip', 'building', 'floor'. In props.conf, they set: `LOOKUP-1 = devices ip OUTPUT building floor`. In transforms.conf: `[devices] filename = devices.csv`. The search over sourcetype 'network_logs' returns events with the 'ip' field, but 'building' and 'floor' are missing. The admin confirms the CSV file exists and has data. What is the most likely issue?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.