<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why are there duplicate MV fields with JSON data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicate-MV-fields-with-JSON-data/m-p/622315#M107134</link>
    <description>&lt;P&gt;Hello there!&lt;/P&gt;
&lt;P&gt;I'm trying to ingest JSON data via the Splunk Add-on for Microsoft Cloud Services app.&amp;nbsp; I created a sourcetype with INDEXED_EXTRACTIONS=json and left all other settings to their default values.&amp;nbsp; The data got ingested, however, when I table my events I start seeing mv fields with duplicate data.&amp;nbsp; I'm even seeing the "Interesting Fields" section add up to 200% (instead of the expected 100%).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Sourcetype settings" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22674i6B4BE65C5216B863/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sourcetype_settings.PNG" alt="Sourcetype settings" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Sourcetype settings&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Interesting Fields" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22676iEED9A8FE2610BBE4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="interesting_fields.PNG" alt="Interesting Fields" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Interesting Fields&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="MV Fields with duplicate data" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22677iC50D7F5B5DD4D939/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mvfields.PNG" alt="MV Fields with duplicate data" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;MV Fields with duplicate data&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/JSON-format-Duplicate-value-in-field/m-p/306811" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/JSON-format-Duplicate-value-in-field/m-p/306811&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I then followed the advice given in this post ^^^ (i.e., setting KV_MODE=none, AUTO_KV_JSON=false, etc.) but the issue persists.&lt;/P&gt;
&lt;P&gt;I have attached screenshots to this post to better understand my situation.&amp;nbsp; I'm currently on Splunk Cloud.&lt;/P&gt;
&lt;P&gt;Any help with this is greatly appreciated&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 13:59:27 GMT</pubDate>
    <dc:creator>pcontreras</dc:creator>
    <dc:date>2022-11-29T13:59:27Z</dc:date>
    <item>
      <title>Why are there duplicate MV fields with JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicate-MV-fields-with-JSON-data/m-p/622315#M107134</link>
      <description>&lt;P&gt;Hello there!&lt;/P&gt;
&lt;P&gt;I'm trying to ingest JSON data via the Splunk Add-on for Microsoft Cloud Services app.&amp;nbsp; I created a sourcetype with INDEXED_EXTRACTIONS=json and left all other settings to their default values.&amp;nbsp; The data got ingested, however, when I table my events I start seeing mv fields with duplicate data.&amp;nbsp; I'm even seeing the "Interesting Fields" section add up to 200% (instead of the expected 100%).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Sourcetype settings" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22674i6B4BE65C5216B863/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sourcetype_settings.PNG" alt="Sourcetype settings" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Sourcetype settings&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Interesting Fields" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22676iEED9A8FE2610BBE4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="interesting_fields.PNG" alt="Interesting Fields" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Interesting Fields&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="MV Fields with duplicate data" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22677iC50D7F5B5DD4D939/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mvfields.PNG" alt="MV Fields with duplicate data" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;MV Fields with duplicate data&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/JSON-format-Duplicate-value-in-field/m-p/306811" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/JSON-format-Duplicate-value-in-field/m-p/306811&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I then followed the advice given in this post ^^^ (i.e., setting KV_MODE=none, AUTO_KV_JSON=false, etc.) but the issue persists.&lt;/P&gt;
&lt;P&gt;I have attached screenshots to this post to better understand my situation.&amp;nbsp; I'm currently on Splunk Cloud.&lt;/P&gt;
&lt;P&gt;Any help with this is greatly appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 13:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicate-MV-fields-with-JSON-data/m-p/622315#M107134</guid>
      <dc:creator>pcontreras</dc:creator>
      <dc:date>2022-11-29T13:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicate MV Fields with JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicate-MV-fields-with-JSON-data/m-p/622348#M107138</link>
      <description>&lt;P&gt;One common mistake is described in&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf#Structured_Data_Header_Extraction_and_configuration" target="_blank" rel="noopener"&gt;Structured Data Header Extraction and configuration&lt;/A&gt;.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;PRE&gt;* When 'INDEXED_EXTRACTIONS = JSON' for a particular source type, do not also 
  set 'KV_MODE = json' for that source type. This causes the Splunk software to 
  extract the JSON fields twice: once at index time, and again at search time.
* Default: not set&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 29 Nov 2022 06:10:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicate-MV-fields-with-JSON-data/m-p/622348#M107138</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-11-29T06:10:42Z</dc:date>
    </item>
  </channel>
</rss>

