<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk duplicate events after forwarder running in a container gets restarted in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288530#M6815</link>
    <description>&lt;P&gt;Is the Splunk forwarder reading from NFS or writing its logs to NFS?&lt;BR /&gt;
Check any existing &lt;CODE&gt;inputs.conf&lt;/CODE&gt; for an option called &lt;CODE&gt;crcSalt&lt;/CODE&gt; if this is set it can produce duplicate events.&lt;/P&gt;</description>
    <pubDate>Sun, 26 Mar 2017 19:18:38 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2017-03-26T19:18:38Z</dc:date>
    <item>
      <title>splunk duplicate events after forwarder running in a container gets restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288529#M6814</link>
      <description>&lt;P&gt;We have splunk forwarder running in a docker container and all our workloads which is also running in different containers and writes logs to NFS file mounts on dedicated location. &lt;BR /&gt;
The problem here is , when container running forwarder restarts it simply sees all file as new and reads them again causing duplicate events. &lt;BR /&gt;
I assume the problem here is, when forwarder starts in container it becomes new installation of a forwarder.&lt;BR /&gt;
Can this be solved by persisting forwarder file system(/opt/splunk/splunkforworder/*) ? Or is there any alternative ?  &lt;/P&gt;</description>
      <pubDate>Sun, 26 Mar 2017 17:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288529#M6814</guid>
      <dc:creator>rajholla_optum</dc:creator>
      <dc:date>2017-03-26T17:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: splunk duplicate events after forwarder running in a container gets restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288530#M6815</link>
      <description>&lt;P&gt;Is the Splunk forwarder reading from NFS or writing its logs to NFS?&lt;BR /&gt;
Check any existing &lt;CODE&gt;inputs.conf&lt;/CODE&gt; for an option called &lt;CODE&gt;crcSalt&lt;/CODE&gt; if this is set it can produce duplicate events.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Mar 2017 19:18:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288530#M6815</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2017-03-26T19:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: splunk duplicate events after forwarder running in a container gets restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288531#M6816</link>
      <description>&lt;P&gt;Thank you for your time ! &lt;/P&gt;

&lt;P&gt;Forwarder reading log files from NFS.&lt;BR /&gt;
Forwarder writes everything  into container write layer which wont be persisted after restart. &lt;BR /&gt;
We are not using &lt;STRONG&gt;crcSlat&lt;/STRONG&gt; in our inputs.conf&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 01:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288531#M6816</guid>
      <dc:creator>rajholla_optum</dc:creator>
      <dc:date>2017-03-27T01:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: splunk duplicate events after forwarder running in a container gets restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288532#M6817</link>
      <description>&lt;P&gt;if persisting the forwarder is possible (im not a docker guy) then it would solve the issue as Splunk would then remember where it was in each of the files. check out the fishbucket!&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2008/08/14/what-is-this-fishbucket-thing/"&gt;https://www.splunk.com/blog/2008/08/14/what-is-this-fishbucket-thing/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 01:22:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288532#M6817</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-03-27T01:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunk duplicate events after forwarder running in a container gets restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288533#M6818</link>
      <description>&lt;P&gt;After persisting "/opt/splunk/splunkforwarder" forwarder was able to read the files at specific offset. &lt;BR /&gt;
Information about &lt;STRONG&gt;fishbucket&lt;/STRONG&gt; was very really helpful. &lt;/P&gt;

&lt;P&gt;Thank you! &lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 17:19:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288533#M6818</guid>
      <dc:creator>rajholla_optum</dc:creator>
      <dc:date>2017-03-27T17:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk duplicate events after forwarder running in a container gets restarted</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288534#M6819</link>
      <description>&lt;P&gt;I would also be very concerned the NFS portion of this solution would allow for loss of logs if a close happens without the proper time for flushing to occur. Normally streaming to remote mounts is considered a bad practice. Consider the use of the splunk docker log driver for OS logs and other means of streaming delivery such rsyslog or HEC to avoid the file IO.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 17:29:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/splunk-duplicate-events-after-forwarder-running-in-a-container/m-p/288534#M6819</guid>
      <dc:creator>rfaircloth_splu</dc:creator>
      <dc:date>2017-03-27T17:29:39Z</dc:date>
    </item>
  </channel>
</rss>

