My inputs.conf is:
[monitor:///var/log/grains.log]
sourcetype = grains_log
disabled = 0
index = os
My props.conf is as follows:
[grains_log]
INDEXED_EXTRACTIONS = json
KV_MODE = none
But I keep seeing double values.
Does someone has an idea what I miss here ?
-- double values
What do you mean by that? do you see the events once and twice the count of values on the fields side bar?
while you can find the solution, you can use "| dedup _raw" to remove duplicates,
These questions should help answer yours. The INDEXED_EXTRACTIONS = json should be located where the data is being indexed. If the search head is on a different system from where the indexing is taking place then you will also need the props.conf for that sourcetype on the search head specifying KV_MODE = none. It's likely you are getting both index time and search time extractions for the JSON data.
You may consider converting this to an answer.
Where does this props.conf resides? Do you've dedicated search heads?