<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: duplicate JSON are coming in search in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531741#M89441</link>
    <description>&lt;P&gt;Are you perhaps using Verbose Mode?&lt;/P&gt;&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;INDEXED_EXTRACTIONS=json&lt;/FONT&gt; setting tells Splunk to extract fields from each event at index time.&amp;nbsp; A Verbose Mode search then automatically extracts fields at search time.&amp;nbsp; The result is duplicates.&lt;/P&gt;</description>
    <pubDate>Wed, 02 Dec 2020 16:47:58 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-12-02T16:47:58Z</dc:date>
    <item>
      <title>duplicate JSON are coming in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531700#M89431</link>
      <description>&lt;P&gt;I have a json file like below&lt;/P&gt;&lt;P&gt;{"env":"UAT","label":"jenkins-17887.api.v2.dm.btc","App":"dm-d-services","rlmtemplate":"f2_api_fed","lastupdate":2020-11-23 11:09:78:455,"region":"APAC"}{"env":"UAT","label":"jenkins-17687.api.v2.dm.btc","App":"dt-s-services","rlmtemplate":"f3_api_fed","lastupdate":2020-11-23 11:025:79:475,"region":"APAC"}{"env":"UAT","label":"jenkins-18657.api.v2.dm.btc","App":"dt-s-services","rlmtemplate":"f3_api_fed","lastupdate":2020-11-23 11:025:79:475,"region":"APAC"}{"env":"UAT","label":"jenkins-17637.api.v2.dm.btc","App":"dt-s-services","rlmtemplate":"f3_api_fed","lastupdate":2020-11-23 11:025:79:475,"region":"APAC"}&lt;/P&gt;&lt;P&gt;in splunk,&lt;/P&gt;&lt;P&gt;_raw contains valid json data for all events.&lt;/P&gt;&lt;P&gt;issue is all fields are multi valued containing two copies of the json object.&lt;/P&gt;&lt;P&gt;forwarding json data to splunk and props is installed on indexer not in heavy forwarder,&lt;/P&gt;&lt;P&gt;props.conf&lt;/P&gt;&lt;P&gt;[test_json]&lt;/P&gt;&lt;P&gt;INDEXED_EXTRACTIONS = JSON&lt;/P&gt;&lt;P&gt;KV_MODE = none&lt;/P&gt;&lt;P&gt;AUTO_KV_JSON = false&lt;/P&gt;&lt;P&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P&gt;FYI , using splunk 8.0&lt;/P&gt;&lt;P&gt;tried by setting KV_MODE = JSON&amp;nbsp; but it is also not working&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 16:14:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531700#M89431</guid>
      <dc:creator>kirrusk</dc:creator>
      <dc:date>2020-12-02T16:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: duplicate JSON are coming in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531723#M89434</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;In splunk it's showing one event but while applying query on it , like query | table fields&lt;P&gt;duplicate values are coming in fields&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;How is Splunk showing one event without a query?&amp;nbsp; What is the query you use that is showing duplicate values?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 15:48:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531723#M89434</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-02T15:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: duplicate JSON are coming in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531731#M89437</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; updated question&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 16:14:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531731#M89437</guid>
      <dc:creator>kirrusk</dc:creator>
      <dc:date>2020-12-02T16:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: duplicate JSON are coming in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531741#M89441</link>
      <description>&lt;P&gt;Are you perhaps using Verbose Mode?&lt;/P&gt;&lt;P&gt;The &lt;FONT face="courier new,courier"&gt;INDEXED_EXTRACTIONS=json&lt;/FONT&gt; setting tells Splunk to extract fields from each event at index time.&amp;nbsp; A Verbose Mode search then automatically extracts fields at search time.&amp;nbsp; The result is duplicates.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 16:47:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531741#M89441</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-12-02T16:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: duplicate JSON are coming in search</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531806#M89452</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp; Can u pls suggest how can i rectify this, it is running in verbose mode. I changed to fast mode and smart mode but duplicates are still coming&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 05:20:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-JSON-are-coming-in-search/m-p/531806#M89452</guid>
      <dc:creator>kirrusk</dc:creator>
      <dc:date>2020-12-03T05:20:47Z</dc:date>
    </item>
  </channel>
</rss>

