Getting Data In

independent stream forwarder field value duplication problem

luckinfo
Engager

The field value is duplicated in independent Stream forwarder. Is there a workaround?

  • Version Splunk 6.5.5 and independent Stream forwarder 7.1.1

alt text

Tags (1)
0 Karma

harsmarvania57
Ultra Champion

This looks like INDEXED_EXTRACTIONS = JSON on UF side and KV_MODE = auto (This is default) or KV_MODE = json on search head is present and due to that it is extracting JSON event twice.

You need to set KV_MODE = none on search head for your sourcetype so search head will not extract this JSON event again.

On SH props.conf

[yoursourcetype]
KV_MODE = none

nickhills
Ultra Champion

Is this forwarded with useAck = true set on the forwarders outputs.conf?

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

Scratch my comment - i misread 'field duplicated' as 'event duplicated'

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...