<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alerts - results.fieldname duplicated? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alerts-results-fieldname-duplicated/m-p/536260#M10127</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49683"&gt;@poiromaniax&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If there is no typo, I can see User field is not duplicated. Is it possible that you alert result has multi-values grouped by userName ? If not can you please share your alert search?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jan 2021 20:22:11 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-01-18T20:22:11Z</dc:date>
    <item>
      <title>Alerts - results.fieldname duplicated?</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-results-fieldname-duplicated/m-p/536190#M10126</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a strange issue that I cant seem to find any info on and I'm hoping someone can help me.&lt;/P&gt;&lt;P&gt;I have a few alerts that are sent to Slack using the&amp;nbsp;&lt;SPAN&gt;slack_alerts addon from Splunkbase.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Recently,&amp;nbsp; the results of these alerts are duplicated within the alert itself. (I am not receiving multiple of the same alert individually)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This is the alert config:&lt;/P&gt;&lt;P&gt;AWS Authentication Failed&lt;/P&gt;&lt;P&gt;*Time:* $result.eventTime$&lt;/P&gt;&lt;P&gt;*Event:* $result.eventName$&lt;/P&gt;&lt;P&gt;*Account:* $result.recipientAccountId$&lt;/P&gt;&lt;P&gt;*User:* $result.userName$&lt;/P&gt;&lt;P&gt;*Source IP:* $result.sourceIPAddress$&lt;/P&gt;&lt;P&gt;*EventID:* $result.eventID$&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the result:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;AWS Authentication Failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Time:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;2021-01-18T10:40:16Z&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2021-01-18T10:40:16Z&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Event:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;AssumeRoleWithSAML&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AssumeRoleWithSAML&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Account:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;22xxxxxxxxxx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;22xxxxxxxxxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;User:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;xxxxxxxxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Source IP:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;54.89.xxxxxxx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;54.89.xxxxxxxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EventID:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;862b7079-e38b-4b1e-xxxxxxxxx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;862b7079-e38b-4b1e-xxxxxxxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried recreating the alerts, removing and readding the Slack addon but same behaviour&lt;/P&gt;&lt;P&gt;Hoping someone can help!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 11:07:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-results-fieldname-duplicated/m-p/536190#M10126</guid>
      <dc:creator>poiromaniax</dc:creator>
      <dc:date>2021-01-18T11:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts - results.fieldname duplicated?</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-results-fieldname-duplicated/m-p/536260#M10127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/49683"&gt;@poiromaniax&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If there is no typo, I can see User field is not duplicated. Is it possible that you alert result has multi-values grouped by userName ? If not can you please share your alert search?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2021 20:22:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-results-fieldname-duplicated/m-p/536260#M10127</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-18T20:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: Alerts - results.fieldname duplicated?</title>
      <link>https://community.splunk.com/t5/Alerting/Alerts-results-fieldname-duplicated/m-p/536480#M10133</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;thanks for the response.&lt;/P&gt;&lt;P&gt;I expanded all fields and I cannot see any duplicates.&lt;/P&gt;&lt;P&gt;I also sent the alert via email in case it was specific to Slack, but same result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Search is:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=aws tag=authentication NOT (action=success user=*$)
| search (action="failure")  src_user!=unknown
| search "requestParameters.roleArn"!="arn:aws:iam:xxxxxxxxxxxxx"
| search "requestParameters.roleSessionName"!=xxxxxxxxxxxxx&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 20 Jan 2021 12:09:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alerts-results-fieldname-duplicated/m-p/536480#M10133</guid>
      <dc:creator>poiromaniax</dc:creator>
      <dc:date>2021-01-20T12:09:12Z</dc:date>
    </item>
  </channel>
</rss>

