Getting Data In

How to correct fields extracted twice ?



I made a mistake during on migration on data source. I moved from csv format to json.

Suppose the migration date is day A.

On that day, I have in my props.conf (the one on the indexer cluster)



When I looked at the result on the Search Cluster, the field where displayed twice.

I missed the props.conf on the SHC saying :


KV_MODE = json.


So on day B : I rolled back => and deleted the "INDEXED_EXTRACTIONS" from the props.conf file on the IDX cluster.


Since day B : results are perfectly fine.



When I look at events between A and B period => the fields are displayed twice.

I need to keep the KV_MODE on, because otherwise, I cannot extract any data when searching (no extraction made at index time before day A and after day B).

As a results, all calculus using part of period between A and B are false. I even get percentage > 100%.


Question is :

- do you have any idea how to fix this so the results of the splunk command will be ok (I can't believe I'm the only one to face this wall).

- is there any way to delete the extracted fields withour deleting (masking) the data ?


Thanks everyone,



Labels (1)
Tags (2)
0 Karma
1 Solution


You cannot change the sourcetype once the data has been indexed. You'll need to delete it and re-ingest.

An upvote would be appreciated and Accept Solution if it helps!

View solution in original post

0 Karma


You cannot change the sourcetype once the data has been indexed. You'll need to delete it and re-ingest.

An upvote would be appreciated and Accept Solution if it helps!
0 Karma



Thanks, I'm currently doing this one.

But, I'd hoped for another solution as I keep storing "faulty" data even though it's useless.

(Plus, this is not easy doing that on prod env).


0 Karma
Get Updates on the Splunk Community!

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...