Splunk Search

Json duplication fields on a clustered set up environment

emcglade
Engager

Afternoon,

We are currently having issues with duplicate JSON entries on our search heads which operate in a clustered set up. I understand this is due to the data being read at index time and at search time, hence duplicating the fields. 

I have read many other forums with similar issues. The fix suggested is to ensure to set the below in the props.conf on the search heads which we have deployed via an app.

KV_MODE =  none 

AUTO_KV_JSON = false 

while keeping just the below on the props.conf on the forwarder;

INDEXED_EXTRACTIONS = JSON 


We have successfully tested this in a non clustered environment and it seems to work but in a clustered set up we are still seeing the duplicate values.

 

Any help or guidance would be greatly appreciated. 



Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...