<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does my search that checks for extract yield events twice with two different timestamps? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-my-search-that-checks-for-extract-yield-events-twice/m-p/360109#M65658</link>
    <description>&lt;P&gt;I recently setup Splunk Dashboard integrated with Tableau, when i run below mentioned query it gives me a count of successful extract for today.&lt;/P&gt;

&lt;P&gt;host=TABLEAU   splunk_server="ip-XX-XXX-X-XXX" "(XXXX,,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: AAAAA_AAAAAAPrgExtensions/extract" | stats count.&lt;/P&gt;

&lt;P&gt;But recently when the query ran it shows two results for same extract when it should be 1, also,if you see both the events closely even though it has a date of 09/27/2017 but inside it displays date_mday =   27 for the second query result date_mday =  26. What can i add to the query where it does not duplicate and display Today results&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;9/27/17
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;7:30:04.734 AM&lt;BR /&gt;&lt;BR /&gt;
2017-09-27 03:30:04.734 -0400 (XXXX,,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: XXXXXXPrgExtensions/extract repoExtractId:17503 size:12572 (twb) + 758672090 (guid={XXXXXXX) = 758684662&lt;BR /&gt;
date_mday = 27 date_month = september date_year =   2017 eventtype =    nix-all-logs host = TABLEAU index = main linecount =    1 punct =   --&lt;EM&gt;::.&lt;/EM&gt;-&lt;EM&gt;(,,,)&lt;/EM&gt;---&lt;EM&gt;:&lt;/EM&gt;&lt;STRONG&gt;....._-&lt;/STRONG&gt;&lt;EM&gt;:&lt;/EM&gt;/&lt;EM&gt;:&lt;/EM&gt;:&lt;EM&gt;()&lt;/EM&gt;+__(={ source = D:\Software\Tableau\Tableau Server\data\tabsvc\logs\backgrounder\backgrounder-1.log sourcetype =    backgrounder/backgrounder-3 splunk_server = ip-XX-XXX-X-XXX unix_category = all_hosts unix_group =  default&lt;/P&gt;

&lt;P&gt;9/27/17&lt;BR /&gt;
12:50:47.694 AM &lt;BR /&gt;
2017-09-26 20:50:47.694 -0400 (XXXXX,,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: XXXXXX/extract repoExtractId:17494 size:12521 (twb) + 758649674 (guid={XXXXXXXX5}) = 758662195&lt;BR /&gt;
date_mday = 26 date_month** =   september date_year =   2017 eventtype =    nix-all-logs host = TABLEAU index = main linecount =    1 punct =   --&lt;EM&gt;::.&lt;/EM&gt;-&lt;EM&gt;(,,,)&lt;/EM&gt;---&lt;EM&gt;:&lt;/EM&gt;&lt;STRONG&gt;....._-&lt;/STRONG&gt;&lt;EM&gt;:&lt;/EM&gt;/&lt;EM&gt;:&lt;/EM&gt;:&lt;EM&gt;()&lt;/EM&gt;+__(={ source = D:\Software\Tableau\Tableau Server\data\tabsvc\logs\backgrounder\backgrounder-1.log sourcetype =    backgrounder/backgrounder-3 splunk_server = ip-10-168-2-185 unix_category = all_hosts unix_group =  default&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:58:01 GMT</pubDate>
    <dc:creator>shakeel253</dc:creator>
    <dc:date>2020-09-29T15:58:01Z</dc:date>
    <item>
      <title>Why does my search that checks for extract yield events twice with two different timestamps?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-my-search-that-checks-for-extract-yield-events-twice/m-p/360109#M65658</link>
      <description>&lt;P&gt;I recently setup Splunk Dashboard integrated with Tableau, when i run below mentioned query it gives me a count of successful extract for today.&lt;/P&gt;

&lt;P&gt;host=TABLEAU   splunk_server="ip-XX-XXX-X-XXX" "(XXXX,,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: AAAAA_AAAAAAPrgExtensions/extract" | stats count.&lt;/P&gt;

&lt;P&gt;But recently when the query ran it shows two results for same extract when it should be 1, also,if you see both the events closely even though it has a date of 09/27/2017 but inside it displays date_mday =   27 for the second query result date_mday =  26. What can i add to the query where it does not duplicate and display Today results&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;9/27/17
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;7:30:04.734 AM&lt;BR /&gt;&lt;BR /&gt;
2017-09-27 03:30:04.734 -0400 (XXXX,,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: XXXXXXPrgExtensions/extract repoExtractId:17503 size:12572 (twb) + 758672090 (guid={XXXXXXX) = 758684662&lt;BR /&gt;
date_mday = 27 date_month = september date_year =   2017 eventtype =    nix-all-logs host = TABLEAU index = main linecount =    1 punct =   --&lt;EM&gt;::.&lt;/EM&gt;-&lt;EM&gt;(,,,)&lt;/EM&gt;---&lt;EM&gt;:&lt;/EM&gt;&lt;STRONG&gt;....._-&lt;/STRONG&gt;&lt;EM&gt;:&lt;/EM&gt;/&lt;EM&gt;:&lt;/EM&gt;:&lt;EM&gt;()&lt;/EM&gt;+__(={ source = D:\Software\Tableau\Tableau Server\data\tabsvc\logs\backgrounder\backgrounder-1.log sourcetype =    backgrounder/backgrounder-3 splunk_server = ip-XX-XXX-X-XXX unix_category = all_hosts unix_group =  default&lt;/P&gt;

&lt;P&gt;9/27/17&lt;BR /&gt;
12:50:47.694 AM &lt;BR /&gt;
2017-09-26 20:50:47.694 -0400 (XXXXX,,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: XXXXXX/extract repoExtractId:17494 size:12521 (twb) + 758649674 (guid={XXXXXXXX5}) = 758662195&lt;BR /&gt;
date_mday = 26 date_month** =   september date_year =   2017 eventtype =    nix-all-logs host = TABLEAU index = main linecount =    1 punct =   --&lt;EM&gt;::.&lt;/EM&gt;-&lt;EM&gt;(,,,)&lt;/EM&gt;---&lt;EM&gt;:&lt;/EM&gt;&lt;STRONG&gt;....._-&lt;/STRONG&gt;&lt;EM&gt;:&lt;/EM&gt;/&lt;EM&gt;:&lt;/EM&gt;:&lt;EM&gt;()&lt;/EM&gt;+__(={ source = D:\Software\Tableau\Tableau Server\data\tabsvc\logs\backgrounder\backgrounder-1.log sourcetype =    backgrounder/backgrounder-3 splunk_server = ip-10-168-2-185 unix_category = all_hosts unix_group =  default&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:58:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-my-search-that-checks-for-extract-yield-events-twice/m-p/360109#M65658</guid>
      <dc:creator>shakeel253</dc:creator>
      <dc:date>2020-09-29T15:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my search that checks for extract yield events twice with two different timestamps?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-my-search-that-checks-for-extract-yield-events-twice/m-p/360110#M65659</link>
      <description>&lt;P&gt;The query ran twice successfully in the time range.  &lt;/P&gt;

&lt;P&gt;In order to dedup them, you will need to identify what part of the event identifies a unique extract.  &lt;/P&gt;

&lt;P&gt;Try this...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;host=TABLEAU splunk_server="ip-XX-XXX-X-XXX" "(XXXX,,,) pool-3-thread-1 : INFO 
com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: AAAAA_AAAAAAPrgExtensions/extract" 
| rex "source = (?&amp;lt;sourcelog&amp;gt;.*.log)" 
| dedup sourcelog
| stats count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Sep 2017 19:12:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-my-search-that-checks-for-extract-yield-events-twice/m-p/360110#M65659</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-09-27T19:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why does my search that checks for extract yield events twice with two different timestamps?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-my-search-that-checks-for-extract-yield-events-twice/m-p/360111#M65660</link>
      <description>&lt;P&gt;The above query didnt give me required results.&lt;BR /&gt;
This is the query i am running, if you closely look the highlighted time stamp, the results are being replicated, what can i add to the query that it wont replicate  date_mday&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;host=TABLEAU "(SEVIS,,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository" | stats count&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;10/13/17&lt;/STRONG&gt;&lt;BR /&gt;
5:03:05.749 AM&lt;BR /&gt;&lt;BR /&gt;
2017-10-13 01:03:05.749 -0400 (ABCDE,,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: SEVIS_UserVerification_Program/extract repoExtractId:17936 size:12999 (twb) + 1709242 (guid={0E61DCE4-54DC-4855-B7D2-ADED09CD280F}) = 1722241&lt;BR /&gt;
&lt;STRONG&gt;date_mday =   13 date_month&lt;/STRONG&gt; =   october date_year = 2017 eventtype =    nix-all-logs host = TABLEAU index = main linecount =    1 punct =   --&lt;EM&gt;::.&lt;/EM&gt;-&lt;EM&gt;(,,,)&lt;/EM&gt;---&lt;EM&gt;:&lt;/EM&gt;&lt;STRONG&gt;....._-&lt;/STRONG&gt;&lt;EM&gt;:&lt;/EM&gt;/&lt;EM&gt;:&lt;/EM&gt;:&lt;EM&gt;()&lt;/EM&gt;+&lt;STRONG&gt;(={ source = D:\Software\Tableau\Tableau Server\data\tabsvc\logs\backgrounder\backgrounder-1.log sourcetype =    backgrounder-0.log splunk_server =  ip-12-123-1-123 unix_category = all_hosts unix_group =  default&lt;BR /&gt;
&lt;STRONG&gt;10/13/17&lt;/STRONG&gt;&lt;BR /&gt;
12:39:41.996 AM &lt;BR /&gt;
2017-10-12 20:39:41.996 -0400 (ABCDE,,) pool-3-thread-1 : INFO  com.tableausoftware.model.workgroup.service.VqlSessionService - Storing to repository: SEVIS_UserVerification_Program/extract repoExtractId:17935 size:13010 (twb) + 1709226 (guid={423E7580-4F13-44FC-8A20-B14A3056FD77}) = 1722236&lt;BR /&gt;
&lt;STRONG&gt;date_mday =   12 date_month&lt;/STRONG&gt; =   october date_year = 2017 eventtype =    nix-all-logs host = TABLEAU index = main linecount =    1 punct =   --&lt;EM&gt;::.&lt;/EM&gt;-&lt;EM&gt;(,,,)&lt;/EM&gt;---_:&lt;/STRONG&gt;&lt;EM&gt;.....&lt;/EM&gt;-&lt;STRONG&gt;&lt;EM&gt;:&lt;/EM&gt;/&lt;EM&gt;:&lt;/EM&gt;:&lt;EM&gt;()&lt;/EM&gt;+&lt;/STRONG&gt;(={ source = D:\Software\Tableau\Tableau Server\data\tabsvc\logs\backgrounder\backgrounder-0.log sourcetype =    backgrounder-0.log splunk_server =  ip-12-123-1-123 unix_category = all_hosts unix_group =  default&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-my-search-that-checks-for-extract-yield-events-twice/m-p/360111#M65660</guid>
      <dc:creator>shakeel253</dc:creator>
      <dc:date>2020-09-29T16:10:15Z</dc:date>
    </item>
  </channel>
</rss>

