SPLK-1003

Full exam simulation

1:00:00
1

Advanced Visualization and Lookups

hard

A Splunk admin notices that a time-based lookup (defined in transforms.conf with time_range=TRUE) is not returning correct results for events outside the lookup's time boundaries. The lookup file contains rows with a valid time range. What is the most likely cause?

0 of 65 answered