<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data from a particular source is extracted in duplicate when searched from &amp;quot;Searching and reporting&amp;quot;? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627407#M107709</link>
    <description>&lt;P&gt;This is a single server Splunk deployment. I am indexing Duo MFA logs using the official splunk app. In the "Searching and reporting" app, when I use the table command to view that data, each field is a multivalue field with the value duplicated. When I try the same search using the Duo app instead of "Searching and reporting", the fields are extracted only once as expected, not duplicated. For example...&lt;/P&gt;
&lt;P&gt;When I use the table command on this data in "Searching and reporting":&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;email
user@example.com
user@example.com&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I use the table command on this data in the "Duo" app:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;email
user@example.com&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So this problem appears to be limited to the&amp;nbsp;"Searching and reporting" app. But I'm not finding any configuration specific to&amp;nbsp;"Searching and reporting" related to this app/source. For example, there is nothing in SPLUNK/etc/apps/search/local/ props.conf or transforms.conf that would affect this source.&lt;/P&gt;
&lt;P&gt;The current configuration according to the btool is coming from SPLUNK/etc/apps/duo_splunkapp/default/props.conf and is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[source::duo]
INDEXED_EXTRACTIONS = json
KV_MODE = none&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried changing the config to this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;INDEXED_EXTRACTIONS = none
AUTO_KV_JSON = true
KV_MODE = json&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but that just resulted in neither the "Searching and reporting" app nor the "Duo" app having extractions for this data. How do I fix this so the "Searching and reporting" app has a single set of extractions and not duplicates?&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jan 2023 18:56:31 GMT</pubDate>
    <dc:creator>joemiller</dc:creator>
    <dc:date>2023-01-18T18:56:31Z</dc:date>
    <item>
      <title>Data from a particular source is extracted in duplicate when searched from "Searching and reporting"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627407#M107709</link>
      <description>&lt;P&gt;This is a single server Splunk deployment. I am indexing Duo MFA logs using the official splunk app. In the "Searching and reporting" app, when I use the table command to view that data, each field is a multivalue field with the value duplicated. When I try the same search using the Duo app instead of "Searching and reporting", the fields are extracted only once as expected, not duplicated. For example...&lt;/P&gt;
&lt;P&gt;When I use the table command on this data in "Searching and reporting":&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;email
user@example.com
user@example.com&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I use the table command on this data in the "Duo" app:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;email
user@example.com&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So this problem appears to be limited to the&amp;nbsp;"Searching and reporting" app. But I'm not finding any configuration specific to&amp;nbsp;"Searching and reporting" related to this app/source. For example, there is nothing in SPLUNK/etc/apps/search/local/ props.conf or transforms.conf that would affect this source.&lt;/P&gt;
&lt;P&gt;The current configuration according to the btool is coming from SPLUNK/etc/apps/duo_splunkapp/default/props.conf and is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[source::duo]
INDEXED_EXTRACTIONS = json
KV_MODE = none&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried changing the config to this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;INDEXED_EXTRACTIONS = none
AUTO_KV_JSON = true
KV_MODE = json&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but that just resulted in neither the "Searching and reporting" app nor the "Duo" app having extractions for this data. How do I fix this so the "Searching and reporting" app has a single set of extractions and not duplicates?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 18:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627407#M107709</guid>
      <dc:creator>joemiller</dc:creator>
      <dc:date>2023-01-18T18:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Data from a particular source is extracted in duplicate when searched from "Searching and reporting"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627414#M107710</link>
      <description>&lt;P&gt;Update: despite the btool not showing anything relevant in&amp;nbsp;&lt;SPAN&gt;SPLUNK/etc/apps/&lt;STRONG&gt;search&lt;/STRONG&gt;/local/props.conf, I added the following lines to that file:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::duo]
AUTO_KV_JSON = false
KV_MODE = none&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and this seems to have fixed my problem. So now my question is why? Why weren't the lines in&amp;nbsp;&lt;SPAN&gt;SPLUNK/etc/apps/&lt;STRONG&gt;duo_splunkapp&lt;/STRONG&gt;/default/props.conf and (&lt;STRONG&gt;duo_splunkapp&lt;/STRONG&gt;/local/props.conf) taking effect even though there were no contradicting lines in a conf file with greater precedence?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 03:37:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627414#M107710</guid>
      <dc:creator>joemiller</dc:creator>
      <dc:date>2023-01-18T03:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Data from a particular source is extracted in duplicate when searched from "Searching and reporting"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627416#M107711</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/141716"&gt;@joemiller&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The issue is using INDEXED_EXTRACTION = json (forwarder/heavy forwarder config) and having&amp;nbsp;KV_MODE = json (search head configuration)&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Admin/Propsconf#Structured_Data_Header_Extraction_and_configuration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.3/Admin/Propsconf#Structured_Data_Header_Extraction_and_configuration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The INDEXED_EXTRACTION setting means the fields are indexed at ingestion time.&amp;nbsp; If this is done then&amp;nbsp;KV_MODE = none (default is auto) should be set on the search head.&amp;nbsp; Also ensure this configuration is globally shared for the sourcetype/source.&lt;BR /&gt;&lt;BR /&gt;In this case the KV_MODE = none had only been shared in the &lt;SPAN&gt;duo_splunkapp&lt;/SPAN&gt; app space, i.e. the search and reporting app does not see this config.&amp;nbsp; To share its config globally: Apps &amp;gt; Manage apps &amp;gt;&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;duo_splunkapp&lt;/SPAN&gt;&amp;nbsp;&amp;gt; Permissions &amp;gt; All apps (system)&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Personally, I would avoid using INDEXED_EXTRACTION and then just let the Splunk search head&amp;nbsp;KV_MODE = auto do all the work at search time - this is considered best practise.&amp;nbsp; Sadly, a lot of third Splunk party apps come with an INDEXED_EXTRACTION enabled and deployed in the default directory.&amp;nbsp; The last time I tired, the only way to disable an INDEXED_EXTRACTION was to remove the line from props.conf in the default folder, i.e. it cannot be disabled in the local directory props.conf with an INDEXED_EXTRACTION = none entry (admittedly, I've not tried this for a while).&amp;nbsp; &amp;nbsp;Not being able to disable it in a local folder means any upgrade of this app in the future will enable it again - unless manually removed again.&lt;BR /&gt;&lt;BR /&gt;Anyway, bit off topic, but you were on the right track with the settings you were playing with.&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 04:12:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627416#M107711</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2023-01-18T04:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: Data from a particular source is extracted in duplicate when searched from "Searching and reporting"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627514#M107720</link>
      <description>&lt;P&gt;Thank you! Argh, so the permissions setting on the app was the reason why my changes weren't taking effect. Thanks for clearing that up for me. And that's confusing about the INDEXED_EXTRACTION not being able to be modified from the local props.conf. I understand why search time extraction mightbe preferable, but I don't want to create a setup that will break when there's an app update either.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 19:28:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Data-from-a-particular-source-is-extracted-in-duplicate-when/m-p/627514#M107720</guid>
      <dc:creator>joemiller</dc:creator>
      <dc:date>2023-01-18T19:28:49Z</dc:date>
    </item>
  </channel>
</rss>

