Hi All,
I have a situation where the date_* fields are being duplicated.
This is affecting all events that come from my heavy forwarder to my indexer.
Example screencap below:
This is surely a bug and certainly fixed by now.
if it makes any difference/help:
forwarder version: 4.1.3 build 80534
indexer version: 4.1.4 build 82143
Not sure of the cause, but interesting that the date_zone
is showing up with two different values...
The search was just:
with the time range restricted to one minute worth of logs.
Can you provide the search that you used in the above example. I suspect this will need to be sent to splunk support.