Splunk Cloud Platform

Splunk Cloud w/ sourcetype = log2metrics_json duplicating results

objectObject
New Member

When I use Splunk to search for events logged by my application I am getting duplicated results with `stats` `table` commands.  Other posts have advised to edit the configuration file. .  I am on Splunk Cloud not using an Universal Forwarder.  After editing the source type configuration (The only configuration I could find within my admin panel & image included below).  I still am getting duplicated results.  I am new to managing my own Splunk instance but willing to learn!

I chose `log2metrics_json` because I interpreted that I would be able to use it to use that to auto-convert values to their types (numbers, booleans, etc).

Thank you,

Screenshot from 2021-04-18 09-19-29.png

Labels (2)
0 Karma

jeremyhagand61
Communicator

Did you resolve this? I have the exact same problem.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...