Getting Data In

Wha is the scripted input duplicate value?

anilkapoor123
Explorer

all fields duplicated which are coming in scripted input output. like below

category

message

priority

timestamp

script output

{"category": "disk space", "message": "'xxx' host '/nsr' disk path occupied with '92.42%' of disk space. Free up the space.", "priority": "warning", "timestamp": "2023-07-03T08:51:25+02:00"}

timestamp is different field then _time. coming in outputs as shown above

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the props.conf stanza for that sourcetype.

How is the timestamp different from _time?

---
If this reply helps you, Karma would be appreciated.
0 Karma

anilkapoor123
Explorer

props.conf

[json_scripted_input]
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
CHARSET=UTF-8
INDEXED_EXTRACTIONS=json
KV_MODE=none
category=Structured
description=Your own JSON definition for networker_alerts.py script
disabled=false
pulldown_type=true
TIME_FORMAT=%Y-%m-%dT%H:%M:%S%:z
TIMESTAMP_FIELDS=timestamp

timestamp is present in scripted input output 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Nothing wrong with those settings, although it's recommended to use SHOULD_LINEMERGE=false with LINE_BREAKER.  Do the indexer/HF and search head use the same props?  If the SH has KV_MODE=json then fields will be duplicated.

---
If this reply helps you, Karma would be appreciated.
0 Karma

anilkapoor123
Explorer

should_line_merge=false does not make any difference in output.

i am not using kv_mode=json in other places . still i am getting duplicate field values.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...