Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why are my json data extracted twice

$
0
0
My inputs.conf is: [monitor:///var/log/grains.log] sourcetype = grains_log disabled = 0 index = os My props.conf is as follows: [grains_log] INDEXED_EXTRACTIONS = json KV_MODE = none But I keep seeing double values. Does someone has an idea what I miss here ?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>