<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I seeing a mismatch between Key-Value and Count after ingesting JSON data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133941#M27533</link>
    <description>&lt;P&gt;Set &lt;CODE&gt;KV_MODE = none&lt;/CODE&gt; and your issue should go away.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Apr 2015 17:28:20 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2015-04-13T17:28:20Z</dc:date>
    <item>
      <title>Why am I seeing a mismatch between Key-Value and Count after ingesting JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133935#M27527</link>
      <description>&lt;P&gt;I have ingested JSON data &amp;amp; Splunk has extracted important fields automatically, but I see some mismatch between Key-Value &amp;amp; Count. There are many such fields with mismatch in count. &lt;/P&gt;

&lt;P&gt;As per my screenshot for a single event, "Count" should be 1 instead of 2.  Could someone advise me how to fix this problem. &lt;BR /&gt;
(i don't see any problem with host, source, sourcetype) &lt;BR /&gt;
props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[json]
KV_MODE = json
INDEXED_EXTRACTIONS = JSON
TRUNCATE = 0
TIME_PREFIX = startTime":
MAX_TIMESTAMP_LOOKAHEAD = 16
SHOULD_LINEMERGE = False
NO_BINARY_CHECK = 0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/301i21E95C59D128F54C/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2015 14:23:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133935#M27527</guid>
      <dc:creator>satishsdange</dc:creator>
      <dc:date>2015-04-13T14:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing a mismatch between Key-Value and Count after ingesting JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133936#M27528</link>
      <description>&lt;P&gt;Can you post some sample entries? &lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2015 15:20:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133936#M27528</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-04-13T15:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing a mismatch between Key-Value and Count after ingesting JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133937#M27529</link>
      <description>&lt;P&gt;Unfortunately, I can't share that data. Would you like to see any config? &lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2015 15:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133937#M27529</guid>
      <dc:creator>satishsdange</dc:creator>
      <dc:date>2015-04-13T15:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing a mismatch between Key-Value and Count after ingesting JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133938#M27530</link>
      <description>&lt;P&gt;If you can mask all the sensitive data, that should do. I'm interested in seeing the format of jSON with the mentioned field. On cursory look, the configuration looks correct. One question though, is this a custom sourcetype? and if yes, could you try renaming it to something else?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2015 15:48:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133938#M27530</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-04-13T15:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing a mismatch between Key-Value and Count after ingesting JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133939#M27531</link>
      <description>&lt;P&gt;I'd say your event contains two Call_Drop values.&lt;/P&gt;

&lt;P&gt;If not, you could post anonymized events.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2015 15:50:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133939#M27531</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-04-13T15:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing a mismatch between Key-Value and Count after ingesting JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133940#M27532</link>
      <description>&lt;P&gt;Here is an event. Important fields have been extracted by Splunk. e.g corCallHeader.firstCellId=1.&lt;BR /&gt;
Then I have used Alias to change it to Cell_ID. &lt;/P&gt;

&lt;P&gt;{"corCallHeader":{"traceId":123456789123456,"startTime":1395736409790,"stopTime":1395736414180,"callDuration":4390,"rnti":0,"imsi":48,"tmsi":962442424,"&lt;/P&gt;

&lt;P&gt;P.S - deleting original log&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2015 16:55:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133940#M27532</guid>
      <dc:creator>satishsdange</dc:creator>
      <dc:date>2015-04-13T16:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I seeing a mismatch between Key-Value and Count after ingesting JSON data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133941#M27533</link>
      <description>&lt;P&gt;Set &lt;CODE&gt;KV_MODE = none&lt;/CODE&gt; and your issue should go away.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2015 17:28:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-seeing-a-mismatch-between-Key-Value-and-Count-after/m-p/133941#M27533</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-04-13T17:28:20Z</dc:date>
    </item>
  </channel>
</rss>

