<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic duplicate host field when _raw is json in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-host-field-when-raw-is-json/m-p/535689#M89841</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm having non-indexed-extracted json in events. When there is a json "host" field host, which is different from the indexed "host", then the search view is showing you 2 values for host in smart or verbose mode.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2021-01-13 um 18.07.19.png" style="width: 934px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12527i6D013DACA2D30101/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2021-01-13 um 18.07.19.png" alt="Bildschirmfoto 2021-01-13 um 18.07.19.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;you can't work with the searchtime extracted json host field - clicking on it gives you no results - as host is an indexed field.&amp;nbsp;&lt;BR /&gt;.. when you are doing a ... | stats count by host, then only "indextimehost" is reported back - as expected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this behaviour differers from "normal" kv searchtime detection:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2021-01-13 um 18.12.01.png" style="width: 716px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12529iAFF6FA4D9002E9B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2021-01-13 um 18.12.01.png" alt="Bildschirmfoto 2021-01-13 um 18.12.01.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i found multiple posts regarding this like:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Duplicate-host-field-after-indexing-JSON-event/m-p/292472" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Duplicate-host-field-after-indexing-JSON-event/m-p/292472&lt;/A&gt;&lt;/P&gt;&lt;P&gt;unfortunately i'm not able to change the json field name at the source. Rewriting is also no good option for me.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This more looks like a display bug for me.. but drives the poweruser crasy.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best Regards,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2021 17:27:32 GMT</pubDate>
    <dc:creator>schose</dc:creator>
    <dc:date>2021-01-13T17:27:32Z</dc:date>
    <item>
      <title>duplicate host field when _raw is json</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-host-field-when-raw-is-json/m-p/535689#M89841</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm having non-indexed-extracted json in events. When there is a json "host" field host, which is different from the indexed "host", then the search view is showing you 2 values for host in smart or verbose mode.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2021-01-13 um 18.07.19.png" style="width: 934px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12527i6D013DACA2D30101/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2021-01-13 um 18.07.19.png" alt="Bildschirmfoto 2021-01-13 um 18.07.19.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;you can't work with the searchtime extracted json host field - clicking on it gives you no results - as host is an indexed field.&amp;nbsp;&lt;BR /&gt;.. when you are doing a ... | stats count by host, then only "indextimehost" is reported back - as expected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this behaviour differers from "normal" kv searchtime detection:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2021-01-13 um 18.12.01.png" style="width: 716px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/12529iAFF6FA4D9002E9B5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2021-01-13 um 18.12.01.png" alt="Bildschirmfoto 2021-01-13 um 18.12.01.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i found multiple posts regarding this like:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Duplicate-host-field-after-indexing-JSON-event/m-p/292472" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Duplicate-host-field-after-indexing-JSON-event/m-p/292472&lt;/A&gt;&lt;/P&gt;&lt;P&gt;unfortunately i'm not able to change the json field name at the source. Rewriting is also no good option for me.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This more looks like a display bug for me.. but drives the poweruser crasy.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best Regards,&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 17:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-host-field-when-raw-is-json/m-p/535689#M89841</guid>
      <dc:creator>schose</dc:creator>
      <dc:date>2021-01-13T17:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: duplicate host field when _raw is json</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-host-field-when-raw-is-json/m-p/536088#M89879</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw host
| eval _raw="{\"host\": \"your host\"}"
| spath&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Automatickey-valuefieldextractionsatsearch-time" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Knowledge/Automatickey-valuefieldextractionsatsearch-time&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In default, KV_MODE=auto. so json is extracted, so if the event has the same name, it will inevitably become.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal | head 1 | fields _raw host
| eval _raw="{\"host\": \"your host\"}"
| eval hostname=spath(_raw,"host")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how about this?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2021 00:08:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-host-field-when-raw-is-json/m-p/536088#M89879</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2021-01-16T00:08:39Z</dc:date>
    </item>
  </channel>
</rss>

