Getting Data In

Values repeated in each field

AnujaJ
Path Finder

I am getting repeated values in Splunk fields. This can be seen only in Table view. For list view/raw there is no repetition seen. However, my search queries treat all these fields as multi-valued fields. I do not want the repeated values in the single valued field.

Values in Splunk
alt text

Props.conf
[kpi_json]
CHARSET=UTF-8
INDEXED_EXTRACTIONS=json
KV_MODE=none
SHOULD_LINEMERGE=true
category=Structured
description=JavaScript Object Notation format. For more information, visit http://json.org/
disabled=false
pulldown_type=true
LINE_BREAKER=([\r\n]+)
TZ=Europe/Berlin
TIMESTAMP_FIELDS=@timestamp

1 Solution

woodcock
Esteemed Legend

Try these settings in props.conf on your Search Heads:

[YourSourcetypeHere]
KV_MODE = none
AUTO_KV_JSON = false

View solution in original post

AnujaJ
Path Finder

I removed Indexed extractions from the prop.conf on UF. And that resolved my issue.

0 Karma

woodcock
Esteemed Legend

Try these settings in props.conf on your Search Heads:

[YourSourcetypeHere]
KV_MODE = none
AUTO_KV_JSON = false

AnujaJ
Path Finder

I have these settings on props.conf on UF. Is that the problem that I need to put these settings on SH?

0 Karma

woodcock
Esteemed Legend

Yes, that is most definitely the problem.

0 Karma

solarboyz1
Builder

It sounds like you want to dedup a multi-value field:

| eval a=dedup(a), b=dedup(b)
0 Karma

AnujaJ
Path Finder

This is not a multivalued field. This is a single valued field. All fields except the date field are affected. I want all the fields to appear as single valued field. The json data has getting wrongly doubled values.

0 Karma

solarboyz1
Builder

What is the search used to generate the table

0 Karma

AnujaJ
Path Finder

index=kpi sourcetype=kpi_json

0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...