Splunk Dev

Unwanted fields are being extracted for search results

MadhuS1
Explorer

I am facing this problem since very beginning. By default fields are being extracted using delimiter '='.

For eg: if an event contains symbol equals "=" in raw text, left side of it will be considered as field name and right part will be treated as field value.

Does this come with default splunk settings? If so how i can manually disable this?
How can avoid seeing these unwanted fields being extracted?

I know we can easily avoid this by All fields ==> Coverage 1% or more. But i still see fields whose coverage is 100%.

Can somebody help me with this? Thanks

Tags (1)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

The default key-value-extraction can be turned off by setting KV_MODE = none in props.conf for that sourcetype.

View solution in original post

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Why would you not want this?

0 Karma

MadhuS1
Explorer

When you do search for a sourcetype, it shows more than 200 fields extracted from urls.
Also it confuses users having less experience on splunk.

In my case events are properly structured and i require no more additional fields.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The default key-value-extraction can be turned off by setting KV_MODE = none in props.conf for that sourcetype.

0 Karma

MadhuS1
Explorer

Thanks martin

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...