Splunk Cloud Platform

Splunk Cloud w/ sourcetype = log2metrics_json duplicating results

objectObject
New Member

When I use Splunk to search for events logged by my application I am getting duplicated results with `stats` `table` commands.  Other posts have advised to edit the configuration file. .  I am on Splunk Cloud not using an Universal Forwarder.  After editing the source type configuration (The only configuration I could find within my admin panel & image included below).  I still am getting duplicated results.  I am new to managing my own Splunk instance but willing to learn!

I chose `log2metrics_json` because I interpreted that I would be able to use it to use that to auto-convert values to their types (numbers, booleans, etc).

Thank you,

Screenshot from 2021-04-18 09-19-29.png

Labels (2)
0 Karma

jeremyhagand61
Communicator

Did you resolve this? I have the exact same problem.

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...