Splunk Search

Why are my json fields extracted twice? (redux)

jamescrowley
New Member

I came across http://answers.splunk.com/answers/174939/why-are-my-json-fields-extracted-twice.html which seemed to describe perfectly the issue, but I've been unable to resolve - as far as I can see, KV_MODE is already set to none.

On our collectors, we have an app with props.conf as follows:

[fundapps_logs]
SHOULD_LINEMERGE = false
TIMESTAMP_FIELDS = datetime
TIME_FORMAT = %m-%d-%Y %H:%M:%S.%l
INDEXED_EXTRACTIONS = json
TRUNCATE = 20000
KV_MODE = none

however, we see two sets of fields in results when we search (but not for the built in splunk fields). If I then do

sourcetype=fundapps_logs | extract

I then see three sets of fields in results. I'm guessing I've got a config issue somewhere.

I've tried adding the same app and props.config to the splunk search/web head (everything runs on a single machine), and restarting but it doesn't appear to have any impact.

Any suggestion?

0 Karma

woodcock
Esteemed Legend

Did you deploy this to your Indexers and after that did you restart all Splunk instances on the Indexers?

0 Karma

somesoni2
Revered Legend

Not sure if you still have this problem, but the answer to this problem is here

https://answers.splunk.com/answers/301893/why-are-several-json-fields-getting-extracted-more.html

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...