I am getting repeated values in Splunk fields. This can be seen only in Table view. For list view/raw there is no repetition seen. However, my search queries treat all these fields as multi-valued fields. I do not want the repeated values in the single valued field.
Values in Splunk
Props.conf
[kpi_json]
CHARSET=UTF-8
INDEXED_EXTRACTIONS=json
KV_MODE=none
SHOULD_LINEMERGE=true
category=Structured
description=JavaScript Object Notation format. For more information, visit http://json.org/
disabled=false
pulldown_type=true
LINE_BREAKER=([\r\n]+)
TZ=Europe/Berlin
TIMESTAMP_FIELDS=@timestamp
Try these settings in props.conf on your Search Heads:
[YourSourcetypeHere]
KV_MODE = none
AUTO_KV_JSON = false
I removed Indexed extractions from the prop.conf on UF. And that resolved my issue.
Try these settings in props.conf on your Search Heads:
[YourSourcetypeHere]
KV_MODE = none
AUTO_KV_JSON = false
I have these settings on props.conf on UF. Is that the problem that I need to put these settings on SH?
Yes, that is most definitely the problem.
It sounds like you want to dedup a multi-value field:
| eval a=dedup(a), b=dedup(b)
This is not a multivalued field. This is a single valued field. All fields except the date field are affected. I want all the fields to appear as single valued field. The json data has getting wrongly doubled values.
What is the search used to generate the table
index=kpi sourcetype=kpi_json