Getting Data In

JSON Double Extraction

ehowardl3
Path Finder

I've got an odd problem with JSON extracting twice. I've read the other posts on this and believe what I have should be working correctly, but it's not.

I have the following props on a universal forwarder, which is reading JSON data:

[Test:JSON]
INDEXED_EXTRACTIONS = json
KV_MODE = none
NO_BINARY_CHECK = true
TIMESTAMP_FIELDS = TimeGenerated
category = Structured
description = JavaScript Object Notation format. For more information, visit http://json.org/
disabled = false
pulldown_type = true

I also have the following on the search head cluster in props:

[Test:JSON]
KV_MODE = none

As I understand it, since I have INDEXED_EXTRACTIONS = json set on the forwarder, it would make sense that I would have double field extractions IF I didn't set KV_MODE = none on the search heads. However, since I do have KV_MODE = none set on the search heads, why am I still getting double extractions? Also, there are no props set on the indexers.

Thanks in advance for any help.

0 Karma

ehowardl3
Path Finder

I even tried copying and pasting the default _json props into the new test sourcetype and still get double extractions, even though the default _json sourcetype does not give me double extractions. This makes no sense to me.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...