i have distributed env. search heads and indexers are in clustering , search heads are not in shclustering heavy forwarder is also there i was testing this script on dev environment before making changes in prod. so i have placed scripted inputs on search head not on HF props.conf is also on search head containing below configs as you mentioned in above post [json_scripted_input] SHOULD_LINEMERGE=true LINE_BREAKER=([\r\n]+) NO_BINARY_CHECK=true CHARSET=UTF-8 INDEXED_EXTRACTIONS=json [on search head] KV_MODE=none [on search head] category=Structured description=Your own JSON definition for networker_alerts.py script disabled=false pulldown_type=true TIME_FORMAT=%Y-%m-%dT%H:%M:%S%:z TIMESTAMP_FIELDS=timestamp #AUTO_KV_JSON=false INDEXED_EXTRACTIONS=json ( when i disable it , category, message and priority field goes fine with single value, but timestamp got 2 values i.e none and timestamp) and when i enable it, all field having duplicates values, timestamp also having duplicate values without none please suggest also let me know if i am not using indexed_extractions=json, how can i convert timestamp into _time
... View more