<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible that the Splunk forwarder caches old events and resends the data again and again? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160651#M32560</link>
    <description>&lt;P&gt;That sounds unlikely as long as indexers are working fine. What's the source field of the repeated data? Can you post the input configuration for that source?&lt;/P&gt;

&lt;P&gt;If your indexers are not working fine and you use &lt;CODE&gt;useAck&lt;/CODE&gt; then there is a small chance of duplicates: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Protectagainstlossofin-flightdata#The_possibility_of_duplicates"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Protectagainstlossofin-flightdata#The_possibility_of_duplicates&lt;/A&gt;&lt;BR /&gt;
...not regularly every five minutes though, and this would be logged in the forwarder's splunkd.log.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Apr 2015 18:41:30 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2015-04-20T18:41:30Z</dc:date>
    <item>
      <title>Is it possible that the Splunk forwarder caches old events and resends the data again and again?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160649#M32558</link>
      <description>&lt;P&gt;We have a batch script which monitors files under some folder and then creates a log file with the file name and file creation time information every 5 mins. Currently, that batch script is creating an empty log file as there are no files in the inspected folder, but there are events coming from that log file to Splunk every 5 minutes. &lt;/P&gt;

&lt;P&gt;Is it possible that the Splunk forwarder caches old events and re-sends again and again?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2015 17:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160649#M32558</guid>
      <dc:creator>sanjay_shrestha</dc:creator>
      <dc:date>2015-04-20T17:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible that the Splunk forwarder caches old events and resends the data again and again?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160650#M32559</link>
      <description>&lt;P&gt;It started at noon and Splunk was getting until 12:55 PM however it stopped after 1 PM. Does this mean anything?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2015 18:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160650#M32559</guid>
      <dc:creator>sanjay_shrestha</dc:creator>
      <dc:date>2015-04-20T18:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible that the Splunk forwarder caches old events and resends the data again and again?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160651#M32560</link>
      <description>&lt;P&gt;That sounds unlikely as long as indexers are working fine. What's the source field of the repeated data? Can you post the input configuration for that source?&lt;/P&gt;

&lt;P&gt;If your indexers are not working fine and you use &lt;CODE&gt;useAck&lt;/CODE&gt; then there is a small chance of duplicates: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Protectagainstlossofin-flightdata#The_possibility_of_duplicates"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.2/Forwarding/Protectagainstlossofin-flightdata#The_possibility_of_duplicates&lt;/A&gt;&lt;BR /&gt;
...not regularly every five minutes though, and this would be logged in the forwarder's splunkd.log.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2015 18:41:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160651#M32560</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-04-20T18:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible that the Splunk forwarder caches old events and resends the data again and again?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160652#M32561</link>
      <description>&lt;P&gt;After sending a data block, the forwarder maintains a copy of the data in its wait queue until it receives an acknowledgment. In the meantime, it continues to send additional blocks as usual. If the forwarder doesn't get acknowledgment for a block within 300 seconds (by default), it closes the connection. You can change the wait time by setting the readTimeout attribute in outputs.conf. &lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 11:58:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-that-the-Splunk-forwarder-caches-old-events-and/m-p/160652#M32561</guid>
      <dc:creator>fdi01</dc:creator>
      <dc:date>2015-04-24T11:58:59Z</dc:date>
    </item>
  </channel>
</rss>

