<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Getting double field name result in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701076#M237845</link>
    <description>&lt;P&gt;If the same search on the same data ran within the same app (are you running both searches from the same app?) yields different results for two different users there must be some difference in configuration. It can be either due to one of the users having custom settings defined on a per user level or difference in permissions to the app the settings (probably either extractions or calculated fields) are defined in.&lt;/P&gt;&lt;P&gt;Compare settings for relevant sourcetype with app and user context using btool.&lt;/P&gt;</description>
    <pubDate>Sat, 05 Oct 2024 07:39:28 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2024-10-05T07:39:28Z</dc:date>
    <item>
      <title>User Getting double field name result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701055#M237839</link>
      <description>&lt;P&gt;User receiving duplicated field names in splunk result for example when i run a search i get an output for the&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;field1=Value1&lt;BR /&gt;and then when the user runs the same search he gets an output of&lt;BR /&gt;field1 = "field1=value1"&lt;BR /&gt;Does any one knows what i need to do to help the user get the same result as mine&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 20:20:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701055#M237839</guid>
      <dc:creator>whitecat001</dc:creator>
      <dc:date>2024-10-04T20:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: User Getting double field name result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701072#M237843</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264928"&gt;@whitecat001&lt;/a&gt;&amp;nbsp;... this looks like a mistaken eval field assignment or table printing issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;pls share with us your search query(remove any sensitive details) and/or the other user's search query.&lt;/P&gt;&lt;P&gt;then troubleshooting this will become easy one, thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 00:25:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701072#M237843</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2024-10-05T00:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: User Getting double field name result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701075#M237844</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Did you create any custom field extraction? If so, check if the field extraction's permissions are set to "global." It might currently be private to you, which could explain why only you're getting the correct results.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 06:55:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701075#M237844</guid>
      <dc:creator>Jawahir</dc:creator>
      <dc:date>2024-10-05T06:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: User Getting double field name result</title>
      <link>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701076#M237845</link>
      <description>&lt;P&gt;If the same search on the same data ran within the same app (are you running both searches from the same app?) yields different results for two different users there must be some difference in configuration. It can be either due to one of the users having custom settings defined on a per user level or difference in permissions to the app the settings (probably either extractions or calculated fields) are defined in.&lt;/P&gt;&lt;P&gt;Compare settings for relevant sourcetype with app and user context using btool.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Oct 2024 07:39:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/User-Getting-double-field-name-result/m-p/701076#M237845</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-10-05T07:39:28Z</dc:date>
    </item>
  </channel>
</rss>

