Splunk Search

User Getting double field name result

whitecat001
Explorer

User receiving duplicated field names in splunk result for example when i run a search i get an output for the       field1=Value1
and then when the user runs the same search he gets an output of
field1 = "field1=value1"
Does any one knows what i need to do to help the user get the same result as mine 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

If the same search on the same data ran within the same app (are you running both searches from the same app?) yields different results for two different users there must be some difference in configuration. It can be either due to one of the users having custom settings defined on a per user level or difference in permissions to the app the settings (probably either extractions or calculated fields) are defined in.

Compare settings for relevant sourcetype with app and user context using btool.

0 Karma

Jawahir
Communicator

Did you create any custom field extraction? If so, check if the field extraction's permissions are set to "global." It might currently be private to you, which could explain why only you're getting the correct results.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @whitecat001 ... this looks like a mistaken eval field assignment or table printing issue. 

pls share with us your search query(remove any sensitive details) and/or the other user's search query.

then troubleshooting this will become easy one, thanks. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...