Greetings community experts Search results for JSON data received via curl and Rest API from AWS are five times the actual events. Seeking help understanding why events are counted more than once. ...
See more...
Greetings community experts Search results for JSON data received via curl and Rest API from AWS are five times the actual events. Seeking help understanding why events are counted more than once. Indexed using sourcetype _JSON Looking at the data Splunk reports 4 deviceConnectivityUpdate events and 1 deviceStateEvent which agrees with the data. However when I run stats count by("hits{}._source.logType") by "hits{}._source.userName I get 5x count of events. Same is true with this search using dedup | eval DCU=mvfilter(match('hits{}._source.logType',"deviceConnectivityUpdate")) | eval DSE=mvfilter(match('hits{}._source.logType',"deviceStateEvent")) | dedup DCU DSE | stats count(DCU) count(DSE) by hits{}._source.userName The data _raw {"total":{"value":5,"relation":"eq"},"max_score":1,"hits":[{"_index":"index_44444444-4444-4444-4444-444444444444","_id":"zbIdu4gBwP_vIV4KexH0","_score":1,"_source":{"version":1,"logType":"deviceConnectivityUpdate","deviceSerialNumber":"4931390007","userName":"gary.whitlocks22","cloudTimestampUTC":"2023-06-14T18:14:11Z","isDeviceOffline":false}},{"_index":"index_44444444-4444-4444-4444-444444444444","_id":"z7Ieu4gBwP_vIV4KARGG","_score":1,"_source":{"version":1,"logType":"deviceConnectivityUpdate","deviceSerialNumber":"4931390007","userName":"gary.whitlocks22","cloudTimestampUTC":"2023-06-14T18:14:45Z","isDeviceOffline":true}},{"_index":"index_44444444-4444-4444-4444-444444444444","_id":"0LIeu4gBwP_vIV4KHxHn","_score":1,"_source":{"version":1,"logType":"deviceStateEvent","deviceSerialNumber":"4931490086","userName":"NSSS","cloudTimestampUTC":"2023-06-14T18:14:53Z","deviceTimestampUTC":"2023-06-14T18:14:55Z","batteryPercent":49,"isCheckIn":false,"isAntiSurveillanceViolation":false,"isLowBatteryViolation":false,"isCellularViolation":false,"isDseDelayed":false,"bleMacAddress":"7d:8e:1a:be:92:5a","cellIpv4Address":"0.0.0.0","cellIpv6Address":"::"}},{"_index":"index_44444444-4444-4444-4444-444444444444","_id":"zrIdu4gBwP_vIV4KsxFQ","_score":1,"_source":{"version":1,"logType":"deviceConnectivityUpdate","deviceSerialNumber":"4931390006","userName":"PennyAndroid","cloudTimestampUTC":"2023-06-14T18:14:25Z","isDeviceOffline":true}},{"_index":"index_44444444-4444-4444-4444-444444444444","_id":"0bIeu4gBwP_vIV4KhBGr","_score":1,"_source":{"version":1,"logType":"deviceConnectivityUpdate","deviceSerialNumber":"4931390006","userName":"PennyAndroid","cloudTimestampUTC":"2023-06-14T18:15:19Z","isDeviceOffline":false}}]} JSON format { "total": { "value": 5, "relation": "eq" }, "max_score": 1, "hits": [ { "_index": "index_44444444-4444-4444-4444-444444444444", "_id": "zbIdu4gBwP_vIV4KexH0", "_score": 1, "_source": { "version": 1, "logType": "deviceConnectivityUpdate", "deviceSerialNumber": "4931390007", "userName": "gary.whitlocks22", "cloudTimestampUTC": "2023-06-14T18:14:11Z", "isDeviceOffline": false } }, { "_index": "index_44444444-4444-4444-4444-444444444444", "_id": "z7Ieu4gBwP_vIV4KARGG", "_score": 1, "_source": { "version": 1, "logType": "deviceConnectivityUpdate", "deviceSerialNumber": "4931390007", "userName": "gary.whitlocks22", "cloudTimestampUTC": "2023-06-14T18:14:45Z", "isDeviceOffline": true } }, { "_index": "index_44444444-4444-4444-4444-444444444444", "_id": "0LIeu4gBwP_vIV4KHxHn", "_score": 1, "_source": { "version": 1, "logType": "deviceStateEvent", "deviceSerialNumber": "4931490086", "userName": "NSSS", "cloudTimestampUTC": "2023-06-14T18:14:53Z", "deviceTimestampUTC": "2023-06-14T18:14:55Z", "batteryPercent": 49, "isCheckIn": false, "isAntiSurveillanceViolation": false, "isLowBatteryViolation": false, "isCellularViolation": false, "isDseDelayed": false, "bleMacAddress": "7d:8e:1a:be:92:5a", "cellIpv4Address": "0.0.0.0", "cellIpv6Address": "::" } }, { "_index": "index_44444444-4444-4444-4444-444444444444", "_id": "zrIdu4gBwP_vIV4KsxFQ", "_score": 1, "_source": { "version": 1, "logType": "deviceConnectivityUpdate", "deviceSerialNumber": "4931390006", "userName": "PennyAndroid", "cloudTimestampUTC": "2023-06-14T18:14:25Z", "isDeviceOffline": true } }, { "_index": "index_44444444-4444-4444-4444-444444444444", "_id": "0bIeu4gBwP_vIV4KhBGr", "_score": 1, "_source": { "version": 1, "logType": "deviceConnectivityUpdate", "deviceSerialNumber": "4931390006", "userName": "PennyAndroid", "cloudTimestampUTC": "2023-06-14T18:15:19Z", "isDeviceOffline": false } } ] }