> Source: [sk181221](https://support.checkpoint.com/results/sk/sk181221)

# sk181221 - "time" field shows twice in the log_exporter's Splunk-formatted logs

| Property | Value |
|----------|-------|
| Solution ID | sk181221 |
| Date Created | 2023-07-06 |
| Last Modified | 2023-07-06 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- A log entry created and sent by `log_exporter` shows the "time" field twice, as in this example:   
`test_hostname `**time=1686814797** `|product=SmartConsole|action=Accept|ifdir=outbound|loguid={0x9876x67887x7009653x1234}|origin=xx.x.x.x|sequencenum=1|`**time=1686814797**`|version=5|administrator=a1234567|client_ip=xx.x.x.x|machine=sanity_test|operation=Log Out|operation_number=12|subject=Administrator Login`

## Cause

* The first field is inside the log *header*.
* The second field is inside the log *body*.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
