Splunk Search

All fields are duplicate & MV. Needs to be single value.

ryhluc01
Communicator

Good Morning,

I need to do a stat avg on the time difference between results. Problem is all of my fields are both duplicate and multi-value (MV).
So,
1) Will the fact that every field is duplicate & MV affect the avg?
2) How can I efficiently make all of the data show up as a single field? This has to be within my search query because its a production environment and I do not have access to change how the data coming in.

0 Karma
1 Solution

woodcock
Esteemed Legend

Your data is probably JSON and you are probably creating index-time fields because you are using INDEXED_EXTRACTIONS = json. This is all fine but when you do that, you need to make sure that you set KV_MODE = none for your sourcetype or you will get a 2nd search-time field extraction/creation which will duplicate and multi-value everything.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Your data is probably JSON and you are probably creating index-time fields because you are using INDEXED_EXTRACTIONS = json. This is all fine but when you do that, you need to make sure that you set KV_MODE = none for your sourcetype or you will get a 2nd search-time field extraction/creation which will duplicate and multi-value everything.

0 Karma

ryhluc01
Communicator

Thanks @woodcock where would I find this to be able to edit it?

0 Karma

woodcock
Esteemed Legend

It should be in props.conf on your Search Head. You need CLI (no GUI for this).

0 Karma

ryhluc01
Communicator

Thanks : D

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...