<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Logs are indexed twice in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-are-indexed-twice/m-p/19326#M8401</link>
    <description>&lt;P&gt;In our case, it was due to file parts. Added  blacklist = .(filepart)$ under monitor stanza of inputs.conf file of forwarder node&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2013 06:32:56 GMT</pubDate>
    <dc:creator>strive</dc:creator>
    <dc:date>2013-07-01T06:32:56Z</dc:date>
    <item>
      <title>Logs are indexed twice</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-are-indexed-twice/m-p/19325#M8400</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a simple use case.&lt;BR /&gt;
 1. Place the log file in the directory in forwarder node (LWF node). This directory is monitored for logs.&lt;BR /&gt;
 2. Check if the data is indexed.&lt;/P&gt;

&lt;P&gt;I placed a log file with just 3 events. It worked fine. I checked by writing a splunk query(index=my_raw_index) on search page and it displayed 3 records.&lt;/P&gt;

&lt;P&gt;I cleaned the index. Placed a log file with 100 events. It worked fine. &lt;/P&gt;

&lt;P&gt;I cleaned the index. Placed a log file with 17000 events. When i checked my_raw_index, there were 34000 records.&lt;/P&gt;

&lt;P&gt;I tried again with lesser number of events. For lesser events it works fine, but not for the log files with more events. Why it is duplicating the events.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Strive&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:48:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-are-indexed-twice/m-p/19325#M8400</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2020-09-28T13:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are indexed twice</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-are-indexed-twice/m-p/19326#M8401</link>
      <description>&lt;P&gt;In our case, it was due to file parts. Added  blacklist = .(filepart)$ under monitor stanza of inputs.conf file of forwarder node&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2013 06:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-are-indexed-twice/m-p/19326#M8401</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2013-07-01T06:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Logs are indexed twice</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Logs-are-indexed-twice/m-p/19327#M8402</link>
      <description>&lt;P&gt;In our case, it was due to file parts. Added  blacklist = .(filepart)$ under monitor stanza of inputs.conf file of forwarder node&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2013 06:33:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Logs-are-indexed-twice/m-p/19327#M8402</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2013-07-01T06:33:14Z</dc:date>
    </item>
  </channel>
</rss>

