Hi All, I have a splunk cluster environment where, while pulling data from a source, itgets indexed twice, not as a separate event, but within same event. So all fields have same value coming twice , making it a multivalue field. Same source code works fine on a standalone splunk server but fails on a cluster. I have tried to have props.conf present only in data app of indexer , however, with with that field extraction does not happen. If I keeps props.conf in both HF and data app, field extraction happens but with above issue. Would appreciate if anyone has any lead on this. TIA.
... View more