Getting Data In

Wha is the scripted input duplicate value?

anilkapoor123
Explorer

all fields duplicated which are coming in scripted input output. like below

category

message

priority

timestamp

script output

{"category": "disk space", "message": "'xxx' host '/nsr' disk path occupied with '92.42%' of disk space. Free up the space.", "priority": "warning", "timestamp": "2023-07-03T08:51:25+02:00"}

timestamp is different field then _time. coming in outputs as shown above

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share the props.conf stanza for that sourcetype.

How is the timestamp different from _time?

---
If this reply helps you, Karma would be appreciated.
0 Karma

anilkapoor123
Explorer

props.conf

[json_scripted_input]
SHOULD_LINEMERGE=true
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
CHARSET=UTF-8
INDEXED_EXTRACTIONS=json
KV_MODE=none
category=Structured
description=Your own JSON definition for networker_alerts.py script
disabled=false
pulldown_type=true
TIME_FORMAT=%Y-%m-%dT%H:%M:%S%:z
TIMESTAMP_FIELDS=timestamp

timestamp is present in scripted input output 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Nothing wrong with those settings, although it's recommended to use SHOULD_LINEMERGE=false with LINE_BREAKER.  Do the indexer/HF and search head use the same props?  If the SH has KV_MODE=json then fields will be duplicated.

---
If this reply helps you, Karma would be appreciated.
0 Karma

anilkapoor123
Explorer

should_line_merge=false does not make any difference in output.

i am not using kv_mode=json in other places . still i am getting duplicate field values.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...