<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unexpected results with field values - Splunk Enterprise in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688444#M114651</link>
    <description>&lt;P&gt;What is the search?&lt;/P&gt;</description>
    <pubDate>Thu, 23 May 2024 10:47:49 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-05-23T10:47:49Z</dc:date>
    <item>
      <title>Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688424#M114646</link>
      <description>&lt;P&gt;With some of the events, we are facing the unexpected format of the query results. Actually in the raw event there is no issue at all, and each field is showing their own values. But when it is queried and displayed in the statistics section as results, the values of few fields are displaying incorrectly.&lt;/P&gt;&lt;P&gt;Usually the search results show key-values. But with some events, the search results are showing as "fieldname1=fieldname1=value" and in some cases "fieldname1=fieldname3=value".&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example1: &lt;STRONG&gt;Request_id=Request_id=12345 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(Expected to be -&amp;gt; "Request_id=12345")&lt;/P&gt;&lt;P&gt;Example2: &lt;STRONG&gt;Parent_id=message_id=456&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(Expected to be -&amp;gt; "Parent_id=321")&lt;/P&gt;&lt;P&gt;Example3: &lt;STRONG&gt;Parent_id=category=unknown&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;(Expected to be -&amp;gt; "Parent_id=321")&lt;/P&gt;&lt;P&gt;Is this related with parser or something else? We are unable to find what could be the issue lying over here.&lt;/P&gt;&lt;P&gt;Could anyone please help us on fixing this issue at the earliest?&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 09:13:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688424#M114646</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2024-05-23T09:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688426#M114647</link>
      <description>&lt;P&gt;It looks to like you either have a problem with your data (raw events), your ingest config e.g. transforms.conf or your search query. Unfortunately, since you have shared none of these, it is rather difficult to offer anything more constructive.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 09:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688426#M114647</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T09:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688441#M114648</link>
      <description>&lt;P&gt;If I run a search query, there is no issue with raw events. From the Events tab, everything looks in perfect format and can't say that there is a Data quality issue in the events.&lt;/P&gt;&lt;P&gt;Only when this is visualised from statistics tab I could see this. Also this is happening only with some events in the results set. I have attached the screenshot of the normal results and the results with Data Quality issue.&lt;/P&gt;&lt;P&gt;Expected results with Request Id and other fields.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akarivaratharaj_0-1716459479128.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30933iCF27993D7299164F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akarivaratharaj_0-1716459479128.png" alt="akarivaratharaj_0-1716459479128.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But what it is displaying (Refer the highlighted rows)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akarivaratharaj_3-1716460402285.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30936iA02C58C97BB9C584/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akarivaratharaj_3-1716460402285.png" alt="akarivaratharaj_3-1716460402285.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the event of one of the request ids where the key value pair is as expected format&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akarivaratharaj_4-1716460839107.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30937iB3E8ECF4EBD4FCF3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akarivaratharaj_4-1716460839107.png" alt="akarivaratharaj_4-1716460839107.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:41:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688441#M114648</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2024-05-23T10:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688444#M114651</link>
      <description>&lt;P&gt;What is the search?&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:47:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688444#M114651</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T10:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688445#M114652</link>
      <description>&lt;P&gt;How are the fields extracted?&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:48:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688445#M114652</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T10:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688447#M114654</link>
      <description>&lt;P&gt;I am using just the table command&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;index=main host=* sourcetype=* source=* | table _time, Request_id, Future_id&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:53:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688447#M114654</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2024-05-23T10:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688448#M114655</link>
      <description>&lt;P&gt;So it looks like it is to do with how the fields are extracted. Please can you share these details?&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:54:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688448#M114655</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T10:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688449#M114656</link>
      <description>&lt;P&gt;Also you shared (a picture of) an event which works, but not one which doesn't. Please can you share the raw text of a "failing" event in a code block (rather than a picture) - you can obfuscate any sensitive details as appropriate.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 10:58:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688449#M114656</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T10:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688451#M114657</link>
      <description>&lt;P&gt;Actually I have shared picture of the raw event of the failed ones only (just masked the confidential fields). They look similar to the other events which work.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 11:02:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688451#M114657</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2024-05-23T11:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688454#M114659</link>
      <description>&lt;P&gt;&lt;SPAN&gt;So it looks like it is to do with how the fields are extracted. Please can you share these details?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 11:14:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688454#M114659</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T11:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688460#M114661</link>
      <description>&lt;P&gt;I have observed one more thing with these failed events. In the event section, usually at the end of each event, the default fields like host, sourcetype, etc., will be appended and displayed.&lt;/P&gt;&lt;P&gt;Similarly, in addition to those default fields, I could see the Request_ID field is also displayed in that section after each event. In that place I could see the format of Request_ID is in unexpected form.&lt;/P&gt;&lt;P&gt;Please check the below screenshot (After the field &lt;STRONG&gt;CT=1&lt;/STRONG&gt;, the section of default fields is shown)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="akarivaratharaj_0-1716463332683.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30939i9EBD80212D27B7EC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="akarivaratharaj_0-1716463332683.png" alt="akarivaratharaj_0-1716463332683.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 11:24:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688460#M114661</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2024-05-23T11:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688463#M114662</link>
      <description>&lt;P&gt;This is showing that the fields have been extracted incorrectly.&lt;/P&gt;&lt;P&gt;Yet again I ask if you could please share your configurations which are being used to extract the fields for this sourcetype - this is likely to be where your problem lies, so if you want a resolution, you are going to have to give us more information.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 12:07:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/688463#M114662</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-05-23T12:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unexpected results with field values - Splunk Enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/708007#M117010</link>
      <description>&lt;P&gt;This issue is resolved after making few changes to props.conf where the field extraction is set.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 04:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unexpected-results-with-field-values-Splunk-Enterprise/m-p/708007#M117010</guid>
      <dc:creator>akarivaratharaj</dc:creator>
      <dc:date>2025-01-06T04:45:59Z</dc:date>
    </item>
  </channel>
</rss>

