product
- Why choose Splunk
- Installation record
- price
- Splunk Enterprise Security
- Splunk Phantom (SOAR)
- Splunk ITSI (Next Generation IT Operations)
- Splunk Observability Cloud
- Splunk UBA
- Macnica CSIRT App Basic
- App for Splunk for Financial Institutions
- Splunk Analytics for Hadoop
- About Apps
- Splunk Edge Hub
- What is Splunk
service
- Dashboard/SPL Creation Pack [Implementation/Building Support]
- Version upgrade service [implementation and construction support]
- Smart Security Monitoring App [Original App/Service]
- Splunk × LANSCOPE Original App [Original App/Service]
- Security Monitoring App for Box [Original App/Service]
- Cloud Security Monitoring App [Original App/Service]
Specifications/Technical Information
Application for evaluation machine
- FAQ
Workaround when fields are displayed twice when searching logs in JSON format
- release date
- 2018-06-14
- last updated
- 2023-05-19
- version
- Splunk Enterprise 9.0.4
- Overview
- Workaround when fields are displayed twice when searching logs in JSON format
- Reference information
- content
-
If you have custom defined fields in a source type for ingesting JSON format logs, the fields may appear duplicated when searching the ingested log files.
This is thought to be because fields are extracted during indexing (when data is imported) and also when searching data, resulting in the same field being displayed twice.
To work around this issue, add the following parameter to the props.conf file on the Splunk server that runs the search:
Configuration File
props.conf on the Splunk server that runs the search
(Example of configuration file)
$SPLUNK_HOME/etc/system/local/props.conf
$SPLUNK_HOME/etc/apps/<App名>/local/props.conf*Note: $SPLUNK_HOME for default installation
Linux:/opt/splunk
Windows:C:\Program Files\splunkSettings
[<Name of source type of data with duplicate fields>]
KV_MODE = none<Setting example>
[Source type A]
KV_MODE = noneAfter editing the configuration file, you can have the settings reflected without restarting the system by accessing the URL below and clicking the "refresh" button.
http://<SplunkサーバーのIPアドレス>:8000/debug/refreshthat's all
In charge of Macnica Splunk Co., Ltd.
- TEL:045-476-2010
- E-mail:splunk-sales@macnica.co.jp
Weekdays: 9:00-17:00