<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Duplicate entries in splunk search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527352#M148867</link>
    <description>&lt;P&gt;Hi Splunk experts&lt;/P&gt;&lt;P&gt;I need one help, the splunk search is giving me duplicate entries when I do a search. I have made sure that there are no duplicate events and I have also used dedup in my search. Still it gives me duplicates. Need your help. See the attached image.&lt;/P&gt;&lt;P&gt;Could you please let me know what could be the issue?&lt;/P&gt;&lt;P&gt;Thanks and best regards&lt;/P&gt;&lt;P&gt;Krishna&lt;/P&gt;</description>
    <pubDate>Fri, 30 Oct 2020 17:45:10 GMT</pubDate>
    <dc:creator>krishna_11</dc:creator>
    <dc:date>2020-10-30T17:45:10Z</dc:date>
    <item>
      <title>Duplicate entries in splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527352#M148867</link>
      <description>&lt;P&gt;Hi Splunk experts&lt;/P&gt;&lt;P&gt;I need one help, the splunk search is giving me duplicate entries when I do a search. I have made sure that there are no duplicate events and I have also used dedup in my search. Still it gives me duplicates. Need your help. See the attached image.&lt;/P&gt;&lt;P&gt;Could you please let me know what could be the issue?&lt;/P&gt;&lt;P&gt;Thanks and best regards&lt;/P&gt;&lt;P&gt;Krishna&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 17:45:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527352#M148867</guid>
      <dc:creator>krishna_11</dc:creator>
      <dc:date>2020-10-30T17:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate entries in splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527362#M148870</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226100"&gt;@krishna_11&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which is the original format of the log entries? Is it JSON or XML?&lt;/P&gt;&lt;P&gt;Maybe you should validate if the sourcetype contains both INDEXED_EXTRACTIONS and KV_MODE set to JSON/XML. If both of them are set, try removing one of them, such as INDEXED_EXTRACTIONS=JSON and KV_MODE=None.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 18:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527362#M148870</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-10-30T18:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate entries in splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527377#M148871</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The original format of the log entries is JSON.&lt;/P&gt;&lt;P&gt;The sourcetype contains only INDEXED_EXTRACTIONS is set to JSON and I have not set KV_MODE at all.&lt;/P&gt;&lt;P&gt;Are there any other ideas?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Krishna&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 21:26:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527377#M148871</guid>
      <dc:creator>krishna_11</dc:creator>
      <dc:date>2020-10-30T21:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate entries in splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527425#M148880</link>
      <description>&lt;P&gt;Are you able to share your sourcetype configs?&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2020 17:12:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527425#M148880</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-10-31T17:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate entries in splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527427#M148881</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my source type config:&lt;/P&gt;&lt;P&gt;[source::...ta-audit-logs-ingester*.log*]&lt;BR /&gt;sourcetype = taauditlogsingester:log&lt;/P&gt;&lt;P&gt;[source::...ta_audit_logs_ingester*.log*]&lt;BR /&gt;sourcetype = taauditlogsingester:log&lt;/P&gt;&lt;P&gt;[Audit-Logs-Source]&lt;BR /&gt;INDEXED_EXTRACTIONS = json&lt;BR /&gt;SHOULD_LINEMERGE = 0&lt;BR /&gt;category = Splunk App Add-on Builder&lt;BR /&gt;pulldown_type = 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for your help. Greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks and best regards&lt;/P&gt;&lt;P&gt;Krishna&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2020 17:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527427#M148881</guid>
      <dc:creator>krishna_11</dc:creator>
      <dc:date>2020-10-31T17:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate entries in splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527434#M148883</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226100"&gt;@krishna_11&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tested a simple json file with this sourcetype settings:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[test:json]
INDEXED_EXTRACTIONS = json
SHOULD_LINEMERGE = 0
pulldown_type = 1&lt;/LI-CODE&gt;&lt;P&gt;And It returned me duplicated values.&lt;/P&gt;&lt;P&gt;When I added KV_MODE = None to the sourcetype, It parsed the json correctly.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[test:json]
INDEXED_EXTRACTIONS = json
SHOULD_LINEMERGE = 0
KV_MODE = None
pulldown_type = 1&lt;/LI-CODE&gt;&lt;P&gt;I would suggest you to test using the KV_MODE option to validate if It works for you.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 00:54:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527434#M148883</guid>
      <dc:creator>alonsocaio</dc:creator>
      <dc:date>2020-11-01T00:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate entries in splunk search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527590#M148944</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/156088"&gt;@alonsocaio&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been testing and it looks like your solution worked like a charm. Thank you so much for this amazing solution. Greatly appreciate it. I have been trying for quite some time and could not find any solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You are a lifesaver &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;-Krishna&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 19:30:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Duplicate-entries-in-splunk-search/m-p/527590#M148944</guid>
      <dc:creator>krishna_11</dc:creator>
      <dc:date>2020-11-02T19:30:20Z</dc:date>
    </item>
  </channel>
</rss>

