Getting Data In

independent stream forwarder field value duplication problem

luckinfo
Engager

The field value is duplicated in independent Stream forwarder. Is there a workaround?

  • Version Splunk 6.5.5 and independent Stream forwarder 7.1.1

alt text

Tags (1)
0 Karma

harsmarvania57
Ultra Champion

This looks like INDEXED_EXTRACTIONS = JSON on UF side and KV_MODE = auto (This is default) or KV_MODE = json on search head is present and due to that it is extracting JSON event twice.

You need to set KV_MODE = none on search head for your sourcetype so search head will not extract this JSON event again.

On SH props.conf

[yoursourcetype]
KV_MODE = none

nickhills
Ultra Champion

Is this forwarded with useAck = true set on the forwarders outputs.conf?

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

Scratch my comment - i misread 'field duplicated' as 'event duplicated'

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...