Getting Data In

Are there inconsistencies in behavior with the need for INDEXED_EXTRACTIONS?

ddrillic
Ultra Champion

The admin class (lab) says that for json we need the following in the props.conf of the forwarder.

INDEXED_EXTRACTIONS=json

However, I know that for json all works fine even if INDEXED_EXTRACTIONS=json is only at the indexer level and maybe even that is not needed.

Recently at Why does the csv sourcetype work for upload but not via the forwarder?

We realized that INDEXED_EXTRACTIONS = csv is absolutely needed at the forwarder level.

Why is that? It seems that not all pre-defined sourcetypes are treated equally.

0 Karma

ddrillic
Ultra Champion

A related one at Why would INDEXED_EXTRACTIONS=JSON in props.conf be resulting in duplicate values?

@mmodestino says -
- If you use INDEXED_EXTRACTIONS, the props.conf needs to be on the UF

The context is json.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

If you use INDEXED_EXTRACTIONS, you need to make sure you disable any search time field extractions for the same sourcetype.
If you specify INDEXED_EXTRACTIONS=json and KV_MODE=auto/json, for example, you will get duplicate values, because the same fields are extracted twice.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...