Getting Data In

JSON - options either limits/tuncates events OR extract twice.

mjm295
Path Finder

Hi Guys

Pretty new to all this and struggling to understand all the other answers.

I have a cronjob which is extracting CMDB data from service now in json format at 1am each day. its over writes a file. My splunk is monitoring that file. I am expecting 463 results/events. with 90ish fields per event.

I have universal forwarder on a server with internet access which forwards straight to the indexers.

I have tried these settings in props.conf:]

KV_MODE = json
AUTO_KV_JSON = false
NO_BINARY_CHECK = 1
TRUNCATE = 0

BUT using this searches only give me 207 results/events.

So I then tried

INDEXED EXTRACTIONS = JSON
 KV_MODE  = none
 NO_BINARY_CHECK = 1
 TRUNCATE = 0

This gives me the expected 463 events, but the search is extracting the fields twice.

How do I get all the events, with only 1 extracted
is there some sort of LIMIT I can set

0 Karma
1 Solution

mjm295
Path Finder

ok did some more reading and stuck with the second option but added

kvmode = none

to my search head props (for this 1 source,, now I am seeing all results, but only 1 set.

i need to understand the indexed extractions better...

View solution in original post

0 Karma

mjm295
Path Finder

ok did some more reading and stuck with the second option but added

kvmode = none

to my search head props (for this 1 source,, now I am seeing all results, but only 1 set.

i need to understand the indexed extractions better...

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...