all fields duplicated which are coming in scripted input output. like below
category
message
priority
timestamp
script output
{"category": "disk space", "message": "'xxx' host '/nsr' disk path occupied with '92.42%' of disk space. Free up the space.", "priority": "warning", "timestamp": "2023-07-03T08:51:25+02:00"}
timestamp is different field then _time. coming in outputs as shown above
Please share the props.conf stanza for that sourcetype.
How is the timestamp different from _time?
props.conf
[json_scripted_input]
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
CHARSET=UTF-8
INDEXED_EXTRACTIONS=json
KV_MODE=none
category=Structured
description=Your own JSON definition for networker_alerts.py script
disabled=false
pulldown_type=true
TIME_FORMAT=%Y-%m-%dT%H:%M:%S%:z
TIMESTAMP_FIELDS=timestamp
timestamp is present in scripted input output
Nothing wrong with those settings, although it's recommended to use SHOULD_LINEMERGE=false with LINE_BREAKER. Do the indexer/HF and search head use the same props? If the SH has KV_MODE=json then fields will be duplicated.
should_line_merge=false does not make any difference in output.
i am not using kv_mode=json in other places . still i am getting duplicate field values.