Splunk Search

Json duplication fields on a clustered set up environment

emcglade
Engager

Afternoon,

We are currently having issues with duplicate JSON entries on our search heads which operate in a clustered set up. I understand this is due to the data being read at index time and at search time, hence duplicating the fields. 

I have read many other forums with similar issues. The fix suggested is to ensure to set the below in the props.conf on the search heads which we have deployed via an app.

KV_MODE =  none 

AUTO_KV_JSON = false 

while keeping just the below on the props.conf on the forwarder;

INDEXED_EXTRACTIONS = JSON 


We have successfully tested this in a non clustered environment and it seems to work but in a clustered set up we are still seeing the duplicate values.

 

Any help or guidance would be greatly appreciated. 



Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...