Splunk Search

Json duplication fields on a clustered set up environment

emcglade
Engager

Afternoon,

We are currently having issues with duplicate JSON entries on our search heads which operate in a clustered set up. I understand this is due to the data being read at index time and at search time, hence duplicating the fields. 

I have read many other forums with similar issues. The fix suggested is to ensure to set the below in the props.conf on the search heads which we have deployed via an app.

KV_MODE =  none 

AUTO_KV_JSON = false 

while keeping just the below on the props.conf on the forwarder;

INDEXED_EXTRACTIONS = JSON 


We have successfully tested this in a non clustered environment and it seems to work but in a clustered set up we are still seeing the duplicate values.

 

Any help or guidance would be greatly appreciated. 



Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...