<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is JSON Event Data Showing Duplicate Values? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505112#M86065</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm trying to ingest json data but it showing data twice for each event field. I used below in props.conf and not sure what is causing the issue.&lt;/P&gt;
&lt;P&gt;[sourcetype]&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;INDEXED_EXTRACTIONS = json&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;KV_MODE=none&amp;nbsp; #( tried both KV_MODE=json and None)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;SHOULD_LINEMERGE=true&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;pulldown_type=true&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;TIMESTAMP_FIELDS=&amp;lt;timestamp field&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;AUTO_KV_JSON=false&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;NO_BINARY_CHECK = true&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Data in SH:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Title:&amp;nbsp;&amp;nbsp;[RESOLVED] Increased Error Rates&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;[RESOLVED] Increased Error Rates&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Mar 2022 00:29:37 GMT</pubDate>
    <dc:creator>cchange</dc:creator>
    <dc:date>2022-03-03T00:29:37Z</dc:date>
    <item>
      <title>Why is JSON Event Data Showing Duplicate Values?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505112#M86065</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm trying to ingest json data but it showing data twice for each event field. I used below in props.conf and not sure what is causing the issue.&lt;/P&gt;
&lt;P&gt;[sourcetype]&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;INDEXED_EXTRACTIONS = json&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;KV_MODE=none&amp;nbsp; #( tried both KV_MODE=json and None)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;SHOULD_LINEMERGE=true&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;pulldown_type=true&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;TIMESTAMP_FIELDS=&amp;lt;timestamp field&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;AUTO_KV_JSON=false&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;NO_BINARY_CHECK = true&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Data in SH:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Title:&amp;nbsp;&amp;nbsp;[RESOLVED] Increased Error Rates&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;[RESOLVED] Increased Error Rates&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 00:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505112#M86065</guid>
      <dc:creator>cchange</dc:creator>
      <dc:date>2022-03-03T00:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Event Data Showing Duplicate Values</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505114#M86066</link>
      <description>&lt;P data-unlink="true"&gt;Hi,&lt;BR /&gt;The "Data in SH:" doesn't show much. It's linking to you Splunk local instance. Can you correct that and share an example of what you're seeing?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 01:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505114#M86066</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2020-06-19T01:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Event Data Showing Duplicate Values</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505116#M86080</link>
      <description>&lt;P&gt;it's the "INDEXED_EXTRACTIONS"&lt;/P&gt;&lt;P&gt;Splunk is doing search time extractions natively on the JSON data anyway and the indexed extractions are adding the duplicate, as well as using up more disk space, you can remove that config and everything should be fine&lt;/P&gt;&lt;P&gt;pretty sure you could just drop the entire KV_MODE and AUTO_KV_JSON lines as well and search time parsing would still extract all your fields for you&lt;/P&gt;&lt;P&gt;here's an exact config I just setup the other day:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[batch:///opt/logs/*.json.gz]
disabled = false
index = &amp;lt;index&amp;gt;
sourcetype = &amp;lt;sourcetype&amp;gt;
move_policy = sinkhole


[sourcetype]
disabled=false
NO_BINARY_CHECK = true
LINE_BREAKER = &amp;lt;regex&amp;gt;
SHOULD_LINEMERGE = false
TRUNCATE = 0
DATETIME_CONFIG = &amp;lt;time&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-upvotes appreciated&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":nerd_face:"&gt;🤓&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 01:43:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505116#M86080</guid>
      <dc:creator>marycordova</dc:creator>
      <dc:date>2020-06-19T01:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Event Data Showing Duplicate Values</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505268#M86098</link>
      <description>&lt;P&gt;Thanks for the response but it is not working.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 19:50:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/505268#M86098</guid>
      <dc:creator>cchange</dc:creator>
      <dc:date>2020-06-19T19:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: JSON Event Data Showing Duplicate Values</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/587329#M103178</link>
      <description>&lt;P&gt;this worked for me&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 00:18:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-JSON-Event-Data-Showing-Duplicate-Values/m-p/587329#M103178</guid>
      <dc:creator>jesspetty</dc:creator>
      <dc:date>2022-03-03T00:18:27Z</dc:date>
    </item>
  </channel>
</rss>

