<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help finding a solution to not have duplicated logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598687#M104420</link>
    <description>&lt;P&gt;No. Splunk on its own does not do any form of deduplication. It's up to you to provide the input data in the form you need.&lt;/P&gt;&lt;P&gt;I must say however that I don't quite understand what do you mean by "2 forwarders with the same logs". Some network share and two separate clients mounting it? Why don't you then ingest the logs simply from the source machine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 May 2022 16:00:43 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-05-20T16:00:43Z</dc:date>
    <item>
      <title>How to find a solution to not have duplicated logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598684#M104419</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;
&lt;P&gt;The deal is that I have 2 forwarders that have exactly the same logs (I'm using 2 forwarders not to have a SPOF) and I want to find a solution to not have duplicated logs. I thought of using a load balancer but I just want to know first if there is some config on Splunk that allows to do that please.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Abir&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 16:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598684#M104419</guid>
      <dc:creator>aatik5u</dc:creator>
      <dc:date>2022-05-20T16:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Help finding a solution to not have duplicated logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598687#M104420</link>
      <description>&lt;P&gt;No. Splunk on its own does not do any form of deduplication. It's up to you to provide the input data in the form you need.&lt;/P&gt;&lt;P&gt;I must say however that I don't quite understand what do you mean by "2 forwarders with the same logs". Some network share and two separate clients mounting it? Why don't you then ingest the logs simply from the source machine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 16:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598687#M104420</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-05-20T16:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to find a solution to not have duplicated logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598753#M104424</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244402"&gt;@aatik5u&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;said, there isn't any configuration for avoid duplications.&lt;/P&gt;&lt;P&gt;If you're speaking of network or HEC logs and you cannot use a Load Balancer, you could configure your DNS to distribute logs to both the Forwarders and manage fails.&lt;/P&gt;&lt;P&gt;Here you can find how to do it&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/windows-server/networking/dns/deploy/app-lb" target="_blank"&gt;https://docs.microsoft.com/en-us/windows-server/networking/dns/deploy/app-lb&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 21 May 2022 05:20:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598753#M104424</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-05-21T05:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to find a solution to not have duplicated logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598829#M104435</link>
      <description>&lt;P&gt;Thank you very much for your answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;to answer your question, I have several linux machines that forward their logs to 2 different universal forwarders using syslog, that's why I have the same logs twice. this choice is kind of questionable I agree :/, but there is no specific reason for choosing to forward logs to one universal forwarder than using a universal forwarder on every linux machine&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 06:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598829#M104435</guid>
      <dc:creator>aatik5u</dc:creator>
      <dc:date>2022-05-23T06:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to find a solution to not have duplicated logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598830#M104436</link>
      <description>&lt;P&gt;Thank you very much &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 06:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-find-a-solution-to-not-have-duplicated-logs/m-p/598830#M104436</guid>
      <dc:creator>aatik5u</dc:creator>
      <dc:date>2022-05-23T06:22:57Z</dc:date>
    </item>
  </channel>
</rss>

