<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When adding &amp;quot;KV_MODE=none&amp;quot; to props.conf, how come unwanted field extractions are not being stopped? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414135#M73245</link>
    <description>&lt;P&gt;Yes. I restarted the Splunk service on the forwarder, and stopped/started Splunk on the indexer.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2019 18:31:29 GMT</pubDate>
    <dc:creator>oversight</dc:creator>
    <dc:date>2019-03-04T18:31:29Z</dc:date>
    <item>
      <title>When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414133#M73243</link>
      <description>&lt;P&gt;I am looking for assistance with unwanted fields extracted automatically.&lt;/P&gt;

&lt;P&gt;I am using a custom sourcetype that I added with a field extraction based on regex. This regex extracts four fields: "thread_name", "log_level", "event_category", and "messages". This works correctly, except for when I click the "xx more fields" link under Interesting Fields in the sidebar of search. That is where I see the unwanted fields are listed, and when I examine an event with one of those fields, I can see the field/value pairs are listed under the Event. The four fields specified in my regex are extracted correctly; I just want to suppress the extraction of the "fields" from within the SQL queries.&lt;/P&gt;

&lt;P&gt;Following the advice from another post, I added KV_MODE=none to props.conf on the forwarder and reindexed the data, but the issue still occurred. I then added KV_MODE=none to props.conf on the indexer, and reindexed the data, but I am still seeing key/value pairs extracted from the SQL queries.&lt;/P&gt;

&lt;P&gt;Can you please advise me of any other recommendations to stop this from happening?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:29:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414133#M73243</guid>
      <dc:creator>oversight</dc:creator>
      <dc:date>2020-09-29T23:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414134#M73244</link>
      <description>&lt;P&gt;Did you restart the Splunk service after making those props changes?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 18:26:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414134#M73244</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2019-03-04T18:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414135#M73245</link>
      <description>&lt;P&gt;Yes. I restarted the Splunk service on the forwarder, and stopped/started Splunk on the indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 18:31:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414135#M73245</guid>
      <dc:creator>oversight</dc:creator>
      <dc:date>2019-03-04T18:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414136#M73246</link>
      <description>&lt;P&gt;The &lt;CODE&gt;KV_MODE=none&lt;/CODE&gt; is the search time field extraction setting and should be set on the Search Head. No data re-indexing is required.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 18:42:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414136#M73246</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-03-04T18:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414137#M73247</link>
      <description>&lt;P&gt;You need to deploy this to your Search Head tier, not the Indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 18:45:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414137#M73247</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-04T18:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414138#M73248</link>
      <description>&lt;P&gt;The deployment consists of a single server running Splunk Enterprise, and forwarders installed on various hosts.  Can you confirm if need to deploy this at $SPLUNK_HOME/etc/apps/search/local/props.conf on the server ?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 19:11:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414138#M73248</guid>
      <dc:creator>oversight</dc:creator>
      <dc:date>2019-03-04T19:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414139#M73249</link>
      <description>&lt;P&gt;I deployed it to $SPLUNK_HOME/etc/apps/search/local/props.conf and it worked.   Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 20:24:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414139#M73249</guid>
      <dc:creator>oversight</dc:creator>
      <dc:date>2019-03-04T20:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414140#M73250</link>
      <description>&lt;P&gt;I verified no data re-indexing is required.  Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 20:25:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414140#M73250</guid>
      <dc:creator>oversight</dc:creator>
      <dc:date>2019-03-04T20:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: When adding "KV_MODE=none" to props.conf, how come unwanted field extractions are not being stopped?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414141#M73251</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 20:25:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/When-adding-quot-KV-MODE-none-quot-to-props-conf-how-come/m-p/414141#M73251</guid>
      <dc:creator>oversight</dc:creator>
      <dc:date>2019-03-04T20:25:57Z</dc:date>
    </item>
  </channel>
</rss>

