<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point App for Splunk: duplicated field values in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/632342#M9276</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Are you referring to the raw events that contains duplicates? If it is in the raw event, then it is nothing to do with the TA or Add-on?&amp;nbsp; If it is with the raw event itself, may be worth to check the source of the data that is sending the logs to splunk...&lt;/P&gt;&lt;P&gt;Only these three fields are having the duplicates or any other fields?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Feb 2023 10:37:18 GMT</pubDate>
    <dc:creator>bharathkumarnec</dc:creator>
    <dc:date>2023-02-27T10:37:18Z</dc:date>
    <item>
      <title>Check Point App for Splunk: duplicated field values?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/583923#M8692</link>
      <description>&lt;P&gt;Hi at all,&lt;/P&gt;
&lt;P&gt;I installed the Check Point App for Splunk and I found a strange behaviour:&lt;/P&gt;
&lt;P&gt;at first the name is "Check Point App for Splunk" but the folder name is "TA-check-point-app-for-splunk" ,that's strange: it's an App or a TA?&lt;/P&gt;
&lt;P&gt;But this isn't my problem:&lt;/P&gt;
&lt;P&gt;installing this app I found that, for each event, there are some fields (date, time and rule_action) that are duplicated with the same value, in other words, for each event there is two times the same field and the same value (e.g. rule_action="allowed").&lt;/P&gt;
&lt;P&gt;Has anyone encountered this problem?&lt;/P&gt;
&lt;P&gt;Ciao and thanks,&lt;/P&gt;
&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 14:32:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/583923#M8692</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-27T14:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point App for Splunk: duplicated field values</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/584439#M8694</link>
      <description>&lt;P&gt;I've seen the behavior sometimes when you use `| extract reload=T` in the search but not sure if it's due to that or something else.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 06:23:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/584439#M8694</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-02-10T06:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point App for Splunk: duplicated field values</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/632342#M9276</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Are you referring to the raw events that contains duplicates? If it is in the raw event, then it is nothing to do with the TA or Add-on?&amp;nbsp; If it is with the raw event itself, may be worth to check the source of the data that is sending the logs to splunk...&lt;/P&gt;&lt;P&gt;Only these three fields are having the duplicates or any other fields?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 10:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/632342#M9276</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2023-02-27T10:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point App for Splunk: duplicated field values</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/632498#M9277</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/217978"&gt;@bharathkumarnec&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;no only these three fields.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 07:36:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/632498#M9277</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-28T07:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point App for Splunk: duplicated field values</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/632593#M9278</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have noticed the same behaviour, but when i unistalled the app/addon still i see duplicated fields but they are in my raw event as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Bharath Kumar ASN&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 14:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Check-Point-App-for-Splunk-duplicated-field-values/m-p/632593#M9278</guid>
      <dc:creator>bharathkumarnec</dc:creator>
      <dc:date>2023-02-28T14:12:23Z</dc:date>
    </item>
  </channel>
</rss>

