What must be done in order to use a lookup table in Splunk?
What must be done in order to use a lookup table in Splunk?
In order to use a lookup table in Splunk, the lookup file must be uploaded to Splunk and a lookup definition must be created. This is necessary to properly define how the lookup table should be used and accessed within Splunk searches. Simply copying and pasting the contents into the search bar, or relying on automatic configurations, does not fulfill the necessary requirements for setting up a lookup table in Splunk.
C correct
C. The lookup file must be uploaded to Splunk and a lookup definition must be created.
"All lookup types require a lookup definition. After you create a lookup definition you can invoke the lookup in a search with the lookup command." https://docs.splunk.com/Documentation/Splunk/9.1.2/Knowledge/Aboutlookupsandfieldactions