Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why is my search on JSON data producing duplicate results for each line, except for the date and time?

$
0
0
Hi guys, I have a problem. Every time I try to run the following search, the result is duplicated in each line, but the date and time. What can be? My log is in format JSON. index="my_index" source="my_source" sourcetype="my_sourcetype" | rename field1 , field2, field3, .... | eval Date = strftime(_time, "%d-%m-%Y") | eval Hour = strftime(_time, "%H-%M-%S") | spath output=Rules path=field.sub-field{}.code | table Date, Hour, field1 , field2, field3, .... ![alt text][1] [1]: /storage/temp/73281-splunk-register-duplicated.png

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>