SPLK-1001 Using Fields and Lookups • Set 6
SPLK-1001 Using Fields and Lookups Practice Test 6 — 15 questions with explanations. Free, no signup.
A Splunk user has a lookup file named 'users.csv' that contains the fields 'user_id' and 'department'. The user wants to add the 'department' field to events that contain a 'user_id' field. However, the field in the events is named 'uid' instead of 'user_id'. Which search syntax will correctly add the 'department' field to the events?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.