Splunk Core Certified User — Question 72
What must be done in order to use a lookup table in Splunk?
Answer options
- A. The lookup must be configured to run automatically.
- B. The contents of the lookup file must be copied and pasted into the search bar.
- C. The lookup file must be uploaded to Splunk and a lookup definition must be created.
- D. The lookup file must be uploaded to the etc/apps/lookups folder for automatic ingestion.
Correct answer: C
Explanation
The correct answer is C because it specifies that both uploading the lookup file and creating a lookup definition are necessary steps to use a lookup table in Splunk. Option A is incorrect as automatic running is not a requirement. Option B is wrong because manual copying is not needed. Option D is also incorrect as simply placing the file in a folder does not create the required definition.