<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk show duplicate event but there is only one in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366574#M169905</link>
    <description>&lt;P&gt;Can you share both the searches (ideally screenshots that show the search query, as well as the (relevant part of) the results?&lt;/P&gt;</description>
    <pubDate>Fri, 27 Apr 2018 14:24:25 GMT</pubDate>
    <dc:creator>FrankVl</dc:creator>
    <dc:date>2018-04-27T14:24:25Z</dc:date>
    <item>
      <title>Splunk show duplicate event but there is only one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366573#M169904</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;I'm monitoring a directory with splunk when i search for those events it shows me by example the field id with count =2&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4849i5959D26605255F63/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;but if i search for that id it shows me only one  event , why is this happening?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 14:16:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366573#M169904</guid>
      <dc:creator>darismendy</dc:creator>
      <dc:date>2018-04-27T14:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk show duplicate event but there is only one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366574#M169905</link>
      <description>&lt;P&gt;Can you share both the searches (ideally screenshots that show the search query, as well as the (relevant part of) the results?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 14:24:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366574#M169905</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-04-27T14:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk show duplicate event but there is only one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366575#M169906</link>
      <description>&lt;P&gt;If your data is coming in JSON or some other structured format and you are having fields extracted at index time then you do not need them done at search time. That is likely what is occuring here. On the search head where this is occuring set KV_MODE = none for the sourcetype that this data is in. Then it should only be extracted at index time and not at search time as well.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 14:40:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366575#M169906</guid>
      <dc:creator>mdsnmss</dc:creator>
      <dc:date>2018-04-27T14:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk show duplicate event but there is only one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366576#M169907</link>
      <description>&lt;P&gt;Also make sure that, the time range of both searches are exactly same.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 14:57:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366576#M169907</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-04-27T14:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk show duplicate event but there is only one</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366577#M169908</link>
      <description>&lt;P&gt;Hello thank you for our answer, I'm not making extractions at index time, i'm just only not truncating the incoming data&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 15:07:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-show-duplicate-event-but-there-is-only-one/m-p/366577#M169908</guid>
      <dc:creator>darismendy</dc:creator>
      <dc:date>2018-04-27T15:07:27Z</dc:date>
    </item>
  </channel>
</rss>

