Getting Data In

How to correct fields extracted twice ?

emallinger
Communicator

Hello,

I made a mistake during on migration on data source. I moved from csv format to json.

Suppose the migration date is day A.

On that day, I have in my props.conf (the one on the indexer cluster)

[toto]

INDEXED_EXTRACTIONS = json

When I looked at the result on the Search Cluster, the field where displayed twice.

I missed the props.conf on the SHC saying :

[toto]

KV_MODE = json.

 

So on day B : I rolled back => and deleted the "INDEXED_EXTRACTIONS" from the props.conf file on the IDX cluster.

 

Since day B : results are perfectly fine.

 

BUT :

When I look at events between A and B period => the fields are displayed twice.

I need to keep the KV_MODE on, because otherwise, I cannot extract any data when searching (no extraction made at index time before day A and after day B).

As a results, all calculus using part of period between A and B are false. I even get percentage > 100%.

 

Question is :

- do you have any idea how to fix this so the results of the splunk command will be ok (I can't believe I'm the only one to face this wall).

- is there any way to delete the extracted fields withour deleting (masking) the data ?

 

Thanks everyone,

Regards,

Ema

Labels (1)
Tags (2)
0 Karma
1 Solution

codebuilder
Influencer

You cannot change the sourcetype once the data has been indexed. You'll need to delete it and re-ingest.

----
An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

0 Karma

codebuilder
Influencer

You cannot change the sourcetype once the data has been indexed. You'll need to delete it and re-ingest.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

emallinger
Communicator

Hello,

Thanks, I'm currently doing this one.

But, I'd hoped for another solution as I keep storing "faulty" data even though it's useless.

(Plus, this is not easy doing that on prod env).

Regards,

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...