Knowledge Management

Why are my json data extracted twice

rolfberkenbosch
New Member

My inputs.conf is:

[monitor:///var/log/grains.log]
sourcetype = grains_log
disabled = 0
index = os

My props.conf is as follows:
[grains_log]
INDEXED_EXTRACTIONS = json
KV_MODE = none

But I keep seeing double values.

Does someone has an idea what I miss here ?

Tags (1)
0 Karma

ddrillic
Ultra Champion

-- double values

What do you mean by that? do you see the events once and twice the count of values on the fields side bar?

0 Karma

felipesewaybric
Contributor

while you can find the solution, you can use "| dedup _raw" to remove duplicates,

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

These questions should help answer yours. The INDEXED_EXTRACTIONS = json should be located where the data is being indexed. If the search head is on a different system from where the indexing is taking place then you will also need the props.conf for that sourcetype on the search head specifying KV_MODE = none. It's likely you are getting both index time and search time extractions for the JSON data.

micahkemp
Champion

You may consider converting this to an answer.

0 Karma

somesoni2
Revered Legend

Where does this props.conf resides? Do you've dedicated search heads?

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...