<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does the REST Search in json format returns duplicate results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-REST-Search-in-json-format-returns-duplicate/m-p/510503#M142879</link>
    <description>&lt;P&gt;I'm performing a REST Search that ends with a | table command&lt;/P&gt;
&lt;P&gt;When I configure the script to csv format, I get 5 events. &amp;nbsp;Raw format, 5 events. Splunk Web: 5 statistics/events. &amp;nbsp;But when I switch the format to json, 10 events, 5 of which are duplicates. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any valid reason why json should be any different than all the other types?&lt;/P&gt;
&lt;P&gt;I've read solutions that suggest going to the config files, this is not available to me.&lt;/P&gt;
&lt;P&gt;Hopefully, there is a way inline with my search to tell Splunk that I want, say, &amp;nbsp;just the data that shows up in my table. &amp;nbsp;This would be ideal.&lt;/P&gt;
&lt;P&gt;Thanks so much.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jul 2020 03:41:34 GMT</pubDate>
    <dc:creator>chris94089</dc:creator>
    <dc:date>2020-07-23T03:41:34Z</dc:date>
    <item>
      <title>Why does the REST Search in json format returns duplicate results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-REST-Search-in-json-format-returns-duplicate/m-p/510503#M142879</link>
      <description>&lt;P&gt;I'm performing a REST Search that ends with a | table command&lt;/P&gt;
&lt;P&gt;When I configure the script to csv format, I get 5 events. &amp;nbsp;Raw format, 5 events. Splunk Web: 5 statistics/events. &amp;nbsp;But when I switch the format to json, 10 events, 5 of which are duplicates. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any valid reason why json should be any different than all the other types?&lt;/P&gt;
&lt;P&gt;I've read solutions that suggest going to the config files, this is not available to me.&lt;/P&gt;
&lt;P&gt;Hopefully, there is a way inline with my search to tell Splunk that I want, say, &amp;nbsp;just the data that shows up in my table. &amp;nbsp;This would be ideal.&lt;/P&gt;
&lt;P&gt;Thanks so much.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 03:41:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-REST-Search-in-json-format-returns-duplicate/m-p/510503#M142879</guid>
      <dc:creator>chris94089</dc:creator>
      <dc:date>2020-07-23T03:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: REST Search in json format returns duplicate results</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-does-the-REST-Search-in-json-format-returns-duplicate/m-p/510555#M142893</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Automatickey-valuefieldextractionsatsearch-time" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Knowledge/Automatickey-valuefieldextractionsatsearch-time&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;When KV_MODE is set to auto or auto_escaped, automatic JSON field extraction can take place alongside other automatic key/value field extractions. To disable JSON field extraction without changing the KV_MODE value from auto, add AUTO_KV_JSON=false to the stanza. When not set, AUTO_KV_JSON defaults to true.&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 23 Jul 2020 00:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-does-the-REST-Search-in-json-format-returns-duplicate/m-p/510555#M142893</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-23T00:20:17Z</dc:date>
    </item>
  </channel>
</rss>

