<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duplicate logs in Splunk for multiple sourcetypes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630923#M108145</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;sourcetype = unknown-3" means that in your input sourcetype isn't defines and leaved to Splunk identification.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What's the inputs.conf to take these logs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Feb 2023 08:09:33 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-02-15T08:09:33Z</dc:date>
    <item>
      <title>Duplicate logs in Splunk for multiple sourcetypes?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630751#M108109</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Good day, we are getting&amp;nbsp;Duplicate logs in Splunk for multiple sources with same event example below&lt;/P&gt;
&lt;P&gt;how to avoid duplicate logs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;index=ivz_unix_linux_events _raw="&amp;#27;[34m[2023-02-14 02:22:01.363] [TRACE] shiny-server - &amp;#27;[39mUploading metrics data..."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2/14/23&lt;BR /&gt;1:52:01.363 PM&lt;BR /&gt;&amp;#27;[34m[2023-02-14 02:22:01.363] [TRACE] shiny-server - &amp;#27;[39mUploading metrics data...&lt;BR /&gt;host = usapprstdld101source = /var/log/shiny-server.logsourcetype = shiny-server&lt;BR /&gt;2/14/23&lt;BR /&gt;1:52:01.363 PM&lt;BR /&gt;&amp;#27;[34m[2023-02-14 02:22:01.363] [TRACE] shiny-server - &amp;#27;[39mUploading metrics data...&lt;BR /&gt;host = usapprstdld101source = /var/log/shiny-server.logsourcetype = shiny-server&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 15:33:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630751#M108109</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-15T15:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630753#M108111</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you should analyze the input that generates this log.&lt;/P&gt;&lt;P&gt;Chjeck if there's an input that uses "crcSalt = &amp;lt;SOUCE&amp;gt;" because, without this option, Splunk doesn't index twice a log.&lt;/P&gt;&lt;P&gt;the, are you ingesting logs from a cluster?&lt;/P&gt;&lt;P&gt;Check also if the log is twicy generated by the log source.&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 08:47:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630753#M108111</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-14T08:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630757#M108113</link>
      <description>&lt;P&gt;can you tell how can i check this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 09:09:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630757#M108113</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-14T09:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630765#M108115</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;at first&amp;nbsp;identify the host that generates duplicated logs,&lt;/P&gt;&lt;P&gt;Are your logs from syslog or from a Forwarder?&lt;/P&gt;&lt;P&gt;if from syslog, probably the issue is that you configured the appliance to send to two Splunk servers and you have to disable one of these sendings or (better) use a load balancer.&lt;/P&gt;&lt;P&gt;if you're receiving logs from two hosts, you have a cluster issue, so you have to choose one source to enable, disabling the other.&lt;/P&gt;&lt;P&gt;If instead you have only one host,&amp;nbsp;see inputs.conf using btool (&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.3/Troubleshooting/Usebtooltotroubleshootconfigurations9" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.3/Troubleshooting/Usebtooltotroubleshootconfigurations9&lt;/A&gt;) to understand which configurations generates the duplicated logs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 09:22:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630765#M108115</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-14T09:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630780#M108120</link>
      <description>&lt;P&gt;i can see only one input for this logs source&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/apps/Splunk_TA_nix/local/inputs.conf index = ivz_unix_linux_events&lt;BR /&gt;/opt/splunk/etc/apps/Splunk_TA_nix/local/inputs.conf [monitor:///var/log]&lt;BR /&gt;/opt/splunk/etc/apps/Splunk_TA_nix/local/inputs.conf disabled = false&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 10:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630780#M108120</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-14T10:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630781#M108121</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me summarize:&lt;/P&gt;&lt;P&gt;duplicated logs are from a linux server and there isn't crcSalt in your inputs.conf.&lt;/P&gt;&lt;P&gt;So see in the source of your duplicated logs if they come from the same log file.&lt;/P&gt;&lt;P&gt;if from the same log file, open it and see if the log is generated twice from Linux, in this case you have to intervene in Linux.&lt;/P&gt;&lt;P&gt;if from different log files, identify them and see if you have to blacklist one of them.&lt;/P&gt;&lt;P&gt;Check also if one of the duplicated source files is the other in a zipped file.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuselle&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 10:29:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630781#M108121</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-14T10:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630784#M108122</link>
      <description>&lt;P&gt;can crcsalr resolve this&amp;nbsp;&lt;/P&gt;&lt;P&gt;if yes what is the syntax to add where should i add this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 11:16:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630784#M108122</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-14T11:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630785#M108123</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;crcSalt is useful to reindex already indexed data, because Splunk doesn't index a log twice.&lt;/P&gt;&lt;P&gt;In your case, you have to understand, why you have duplicated logs.&lt;/P&gt;&lt;P&gt;As I said, maybe there's an input with crcSalt so logs are read two times, but follow the debugging steps I hinted.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 11:21:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630785#M108123</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-14T11:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630922#M108144</link>
      <description>&lt;P&gt;nothing as such as mentioned points&amp;nbsp;&lt;/P&gt;&lt;P&gt;one more ex events&amp;nbsp; .see same log&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2/15/23&lt;BR /&gt;1:13:13.000 PM&lt;BR /&gt;"#includedir",&lt;BR /&gt;host = usoraosfclt100source = /etc/insights-client/.cache.jsonsourcetype = unknown-3&lt;BR /&gt;2/15/23&lt;BR /&gt;1:13:13.000 PM&lt;BR /&gt;"#includedir",&lt;BR /&gt;host = usoraosfclt100source = /etc/insights-client/.cache.jsonsourcetype = unknown-3&lt;BR /&gt;2/15/23&lt;BR /&gt;1:09:21.000 PM&lt;BR /&gt;"#includedir",&lt;BR /&gt;host = usoraosfclt100source = /etc/insights-client/.cache.jsonsourcetype = unknown-3&lt;BR /&gt;2/15/23&lt;BR /&gt;1:09:21.000 PM&lt;BR /&gt;"#includedir",&lt;BR /&gt;host = usoraosfclt100source = /etc/insights-client/.cache.jsonsourcetype = unknown-3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 08:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630922#M108144</guid>
      <dc:creator>sekhar463</dc:creator>
      <dc:date>2023-02-15T08:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate logs in Splunk for multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630923#M108145</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244375"&gt;@sekhar463&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;sourcetype = unknown-3" means that in your input sourcetype isn't defines and leaved to Splunk identification.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What's the inputs.conf to take these logs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2023 08:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Duplicate-logs-in-Splunk-for-multiple-sourcetypes/m-p/630923#M108145</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-15T08:09:33Z</dc:date>
    </item>
  </channel>
</rss>

