Getting Data In

JSON events with INDEXED_EXTRACTIONS making each extracted field multivalue

aknsun
Path Finder

Hi,

I have an issue with JSON events having multivalue fields.

We are using scripted input to ingest the data. The scripted input resides on the collector.

I have the following defined in the props.conf on the collector and no where else

[sourcetype_abc]
INDEXED_EXTRACTIONS = json
KV_MODE = none

Going through a few previous posts, it's being advised that KV_MODE = none need to be placed on the Search Head. Can someone confirm this? Do I also need to make use of AUTO_KV_JSON = false?

So does it need to be as follows:
On Collector

[sourcetype_abc]
INDEXED_EXTRACTIONS = json

On SH
[sourcetype_abc]
KV_MODE = none

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi,

Yes configuration which you provided is correct.

On Collector

[sourcetype_abc]
INDEXED_EXTRACTIONS = json

On SH

[sourcetype_abc]
KV_MODE = none

View solution in original post

harsmarvania57
Ultra Champion

Hi,

Yes configuration which you provided is correct.

On Collector

[sourcetype_abc]
INDEXED_EXTRACTIONS = json

On SH

[sourcetype_abc]
KV_MODE = none

aknsun
Path Finder

@harsmarvania57 Thanks. That worked.

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...