<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why table command results with two same values..?? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517694#M34693</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, those fields are all JSON format data.&lt;/P&gt;&lt;P&gt;I run python script in my server, and that python script results in one JSON file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And SplunkUniversal forwarder monitors where the JSON file come out.&lt;/P&gt;&lt;P&gt;And I uploaded props.conf stanza on above reply just now. Please check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2020 10:09:19 GMT</pubDate>
    <dc:creator>splunkkid</dc:creator>
    <dc:date>2020-09-03T10:09:19Z</dc:date>
    <item>
      <title>Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517677#M34689</link>
      <description>&lt;P&gt;Hello.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently kind of confused using splunk enterprise. I am using splunk enterprise 7.2.8 version.&lt;/P&gt;&lt;P&gt;I need to use table command like below, but the command outputs with same 2 values as you can see also as below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[command]&lt;/P&gt;&lt;P&gt;host="myhost" index="myindex" sourcetype="mytype" source="mysource" | table field1, field2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[results - table]&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mv.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10627i824960FB52D5AC98/image-size/large?v=v2&amp;amp;px=999" role="button" title="mv.png" alt="mv.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For your information, our org configured splunk system like below.&lt;/P&gt;&lt;P&gt;splunk universal forwarder -&amp;gt; splunk heavy forwarder -&amp;gt; splunk indexer &amp;lt;- search header&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And above information is sent from server with splunk universal forwarder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea to solve this problem??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 09:24:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517677#M34689</guid>
      <dc:creator>splunkkid</dc:creator>
      <dc:date>2020-09-03T09:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517686#M34690</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225778"&gt;@splunkkid&lt;/a&gt;&amp;nbsp;, could you please advise if these fields are part of json logs? Also, where have you placed the props.conf stanza for these events?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 09:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517686#M34690</guid>
      <dc:creator>Nisha18789</dc:creator>
      <dc:date>2020-09-03T09:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517687#M34691</link>
      <description>&lt;P&gt;This seems to imply that field1 and field2 are either duplicated in the original event, or that the extraction process in duplicating them. You probably need to look at the props and transform configurations&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 09:47:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517687#M34691</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2020-09-03T09:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517693#M34692</link>
      <description>&lt;P&gt;Ok. Thanks for reply.&lt;/P&gt;&lt;P&gt;First of all, it is not just those 2 fields that comes out duplicated. All fields came out like that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And my splunk universal forwarder's path is like below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mv.png" style="width: 675px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/10629iE2724CF67809F679/image-size/large?v=v2&amp;amp;px=999" role="button" title="mv.png" alt="mv.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And props.conf, the file is written like below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[MY_SOURCETYPE]&lt;/P&gt;&lt;P&gt;INDEXED_EXTRACTIONS=JSON&lt;BR /&gt;KV_MODE=none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 10:07:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517693#M34692</guid>
      <dc:creator>splunkkid</dc:creator>
      <dc:date>2020-09-03T10:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517694#M34693</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, those fields are all JSON format data.&lt;/P&gt;&lt;P&gt;I run python script in my server, and that python script results in one JSON file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And SplunkUniversal forwarder monitors where the JSON file come out.&lt;/P&gt;&lt;P&gt;And I uploaded props.conf stanza on above reply just now. Please check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 10:09:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517694#M34693</guid>
      <dc:creator>splunkkid</dc:creator>
      <dc:date>2020-09-03T10:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517700#M34694</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225778"&gt;@splunkkid&lt;/a&gt;&amp;nbsp;, I thnk you are facing duplicate field extractions, as mentioned in this post, please have a look.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Why-is-my-sourcetype-configuration-for-JSON-events-with-INDEXED/td-p/188551" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Why-is-my-sourcetype-configuration-for-JSON-events-with-INDEXED/td-p/188551&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 10:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517700#M34694</guid>
      <dc:creator>Nisha18789</dc:creator>
      <dc:date>2020-09-03T10:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517701#M34695</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/215670"&gt;@Nisha18789&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I have added that props.conf stanza only on Universal forwarder.&lt;/P&gt;&lt;P&gt;From UF, the system forward data to HF and then to Indexer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I didn't added the same stanza to HF or Indexer. I just added that to my UF only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I checked the post you linked.. and changed my props.conf file like below and ran python script again&lt;/P&gt;&lt;P&gt;[MY SOURCETYPE]&lt;BR /&gt;INDEXED_EXTRACTIONS=JSON&lt;BR /&gt;KV_MODE=none&lt;BR /&gt;AUTO_KV_JSON=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the data still results in duplicated format..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 11:07:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517701#M34695</guid>
      <dc:creator>splunkkid</dc:creator>
      <dc:date>2020-09-03T11:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517709#M34697</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225778"&gt;@splunkkid&lt;/a&gt;&amp;nbsp;, could you please add the sourcetype stanza on Search head as well with&amp;nbsp;&lt;SPAN&gt;KV_MODE = none&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 11:44:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517709#M34697</guid>
      <dc:creator>Nisha18789</dc:creator>
      <dc:date>2020-09-03T11:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Why table command results with two same values..??</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517842#M34708</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/215670"&gt;@Nisha18789&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really appreciate your help.&lt;/P&gt;&lt;P&gt;I added to my search header props.conf stanza like below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[MY_SOURCETYPE]&lt;BR /&gt;INDEXED_EXTRACTIONS=JSON&lt;BR /&gt;KV_MODE=none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I am getting right results as I intended!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 01:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-table-command-results-with-two-same-values/m-p/517842#M34708</guid>
      <dc:creator>splunkkid</dc:creator>
      <dc:date>2020-09-04T01:52:00Z</dc:date>
    </item>
  </channel>
</rss>

