Prefer the SH side to what? Have or not have INDEXED_EXTRACTIONS? Depends on what? The needs are simple. We want Splunk to not show duplicated fields when showing JSON data into tables., and be cons...
See more...
Prefer the SH side to what? Have or not have INDEXED_EXTRACTIONS? Depends on what? The needs are simple. We want Splunk to not show duplicated fields when showing JSON data into tables., and be consistent. What is really confusing (and aggravating) about this, is we have other JSON feeds coming in, and those are working just fine. However, each config appears to be different. Sometimes the UF has the props.conf. Sometimes the SH has the props.conf. Sometimes the props.conf has "INDEXED_EXTRACTIONS = JSON" sometimes it doesn't. The whole thing is really confusing as to why Splunk sometimes works properly, and sometimes doesn't. The JSON file is rather large, so put it on pastebin: https://pastebin.com/VwkcdLLA Appreciate your attention with this confusing issue. Let me know if you have any other questions.