<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is my UDP-input data appearing duplicated in the index? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153669#M31234</link>
    <description>&lt;P&gt;I've carried out two searches to find out splunk is indexing duplicate search results which are from the same host, source and sourcetype. &lt;/P&gt;

&lt;P&gt;I know I can use dedup but that only deletes it from the search results which still uses up disk space. I want to know if it's possible to stop splunk from indexing duplicates?&lt;/P&gt;

&lt;P&gt;The two searches i ran to confirm that there were duplicates were:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; - mysearch | stats count values(host) values(source) values(sourcetype) values(index) by _raw | WHERE count&amp;gt;1
 - mysearch | convert ctime(_indextime) AS indextime | table _time indextime _raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help in the right direction would be greatly appreciated. Thanks &lt;/P&gt;</description>
    <pubDate>Tue, 07 Oct 2014 04:15:42 GMT</pubDate>
    <dc:creator>kavraja</dc:creator>
    <dc:date>2014-10-07T04:15:42Z</dc:date>
    <item>
      <title>Why is my UDP-input data appearing duplicated in the index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153669#M31234</link>
      <description>&lt;P&gt;I've carried out two searches to find out splunk is indexing duplicate search results which are from the same host, source and sourcetype. &lt;/P&gt;

&lt;P&gt;I know I can use dedup but that only deletes it from the search results which still uses up disk space. I want to know if it's possible to stop splunk from indexing duplicates?&lt;/P&gt;

&lt;P&gt;The two searches i ran to confirm that there were duplicates were:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; - mysearch | stats count values(host) values(source) values(sourcetype) values(index) by _raw | WHERE count&amp;gt;1
 - mysearch | convert ctime(_indextime) AS indextime | table _time indextime _raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help in the right direction would be greatly appreciated. Thanks &lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 04:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153669#M31234</guid>
      <dc:creator>kavraja</dc:creator>
      <dc:date>2014-10-07T04:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my UDP-input data appearing duplicated in the index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153670#M31235</link>
      <description>&lt;P&gt;You need to provide more information about the original source, otherwise it's very hard to say what causes these events to be duplicates in your index. Splunk will not duplicate events, but it will happily index events if they occur twice.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2014 06:40:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153670#M31235</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-10-07T06:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my UDP-input data appearing duplicated in the index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153671#M31236</link>
      <description>&lt;P&gt;The original source for the logs is content keeper. So whenever a user logs into the vpn for example, the same logs shows up over 150 times with the same time stamp. So basically 150 logs every second from a single user is filling up disk space. An example of the logs coming through are:&lt;/P&gt;

&lt;P&gt;10/9/14 8:36:17.000 AM Oct 9 08:36:17  xxx.xxx.xx.xx.143 09-10-2014; 08:36:15, 26, xxx.xxx.xx.xx, user, 54, 1, text/html, http//somevpn.net default&lt;BR /&gt;
10/9/14 8:36:17.000 AM Oct 9 08:36:17  xxx.xxx.xx.xx.143 09-10-2014; 08:36:15, 26, xxx.xxx.xx.xx, user, 54, 1, text/html, http//somevpn.net default&lt;BR /&gt;
10/9/14 8:36:17.000 AM Oct 9 08:36:17  xxx.xxx.xx.xx.143 09-10-2014; 08:36:15, 26, xxx.xxx.xx.xx, user, 54, 1, text/html, http//somevpn.net default&lt;/P&gt;

&lt;P&gt;The ip and port are all the same.&lt;BR /&gt;
source = udp:516&lt;BR /&gt;
sourcetype = syslog&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2014 01:18:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153671#M31236</guid>
      <dc:creator>kavraja</dc:creator>
      <dc:date>2014-10-09T01:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my UDP-input data appearing duplicated in the index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153672#M31237</link>
      <description>&lt;P&gt;If the data is coming in via UDP then the most likely scenario is duplicate data is coming in via UDP.&lt;/P&gt;

&lt;P&gt;The other possible scenario is this data is coming in over UDP to a forwarder, and something bad is happening in the chain of forwarders to your indexer.  For example, if you have useACK enabled in your forwarder, and the communication to the indexer layer keeps failing, the forwarder will resend data to other indexers to ensure a complete record.&lt;/P&gt;

&lt;P&gt;However, given the reliability of the problem that seems unlikely.&lt;/P&gt;

&lt;P&gt;As next investigative steps I would suggest:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Review the _indextime value of a set of duplicates, ie &lt;CODE&gt;search that gets duplicates | eval visibleindextime=strftime(_indextime, "%Y-%m-%d %H:%M:%S")&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Run tcpdump, wireshark, or similar on the incoming udp stream to see if duplication is there.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153672#M31237</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2020-09-28T17:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my UDP-input data appearing duplicated in the index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153673#M31238</link>
      <description>&lt;P&gt;I ran the first search and got the following results:&lt;/P&gt;

&lt;P&gt;Top 10 Values                     Count&lt;BR /&gt;&lt;BR /&gt;
2014-10-10 08:34:14         -         349&lt;BR /&gt;&lt;BR /&gt;
2014-10-10 08:34:58          -        220&lt;BR /&gt;&lt;BR /&gt;
2014-10-10 08:33:56           -       181&lt;BR /&gt;&lt;BR /&gt;
2014-10-10 08:35:46            -      174   &lt;/P&gt;

&lt;P&gt;and so on and the duplication does appear on the other platforms. I'll keep investigating and see what solution i come up with.&lt;BR /&gt;
Thanks &lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2014 00:49:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153673#M31238</guid>
      <dc:creator>kavraja</dc:creator>
      <dc:date>2014-10-10T00:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why is my UDP-input data appearing duplicated in the index?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153674#M31239</link>
      <description>&lt;P&gt;could you resolve this issue???&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 14:52:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-my-UDP-input-data-appearing-duplicated-in-the-index/m-p/153674#M31239</guid>
      <dc:creator>evinasco</dc:creator>
      <dc:date>2018-08-31T14:52:48Z</dc:date>
    </item>
  </channel>
</rss>

