Splunk Cloud

Splunk Cloud w/ sourcetype = log2metrics_json duplicating results

New Member

When I use Splunk to search for events logged by my application I am getting duplicated results with `stats` `table` commands.  Other posts have advised to edit the configuration file. .  I am on Splunk Cloud not using an Universal Forwarder.  After editing the source type configuration (The only configuration I could find within my admin panel & image included below).  I still am getting duplicated results.  I am new to managing my own Splunk instance but willing to learn!

I chose `log2metrics_json` because I interpreted that I would be able to use it to use that to auto-convert values to their types (numbers, booleans, etc).

Thank you,

Screenshot from 2021-04-18 09-19-29.png

Labels (2)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!