<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to resolve when data getting duplicated twice in indexers? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203576#M40214</link>
    <description>&lt;P&gt;I have the same problem and my version is Splunk Enterprise 6.5.3. Do you have an issue?&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2017 15:37:26 GMT</pubDate>
    <dc:creator>erwan_raulet</dc:creator>
    <dc:date>2017-06-21T15:37:26Z</dc:date>
    <item>
      <title>How to resolve when data getting duplicated twice in indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203571#M40209</link>
      <description>&lt;P&gt;Hi Splunkers,&lt;/P&gt;

&lt;P&gt;I have noticed an issue in my Splunk environment:&lt;/P&gt;

&lt;P&gt;Issue:&lt;/P&gt;

&lt;P&gt;Data is getting duplicated twice in indexers. If i do a search in search head, the same events are coming in twice. this issue started 2 days ago, earlier there is no issue with the data.&lt;/P&gt;

&lt;P&gt;My Investigations:&lt;/P&gt;

&lt;P&gt;1)checked the application logs wether same log is existing twice? Answer: No&lt;BR /&gt;
2)Checked whether this issue is happening to one sourcetype OR only for one index OR one forwarder? Answer: No it is affecting all forwarders and indexers data.&lt;/P&gt;

&lt;P&gt;My questions:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Is the issue is from the Indexer cluster side?&lt;/LI&gt;
&lt;LI&gt;Is the issue is from the forwarder side?&lt;/LI&gt;
&lt;LI&gt;Or any other reason why it is happening?  and what are the steps need to prevent it? &lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Reddy.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 20:23:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203571#M40209</guid>
      <dc:creator>mpreddy</dc:creator>
      <dc:date>2016-11-02T20:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve when data getting duplicated twice in indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203572#M40210</link>
      <description>&lt;P&gt;Something changed in your configuration. Did someone change  outputs.conf. on the forwarders?&lt;BR /&gt;
If no one changed the source data files, then someone must have changed a Splunk setting in some .conf file&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 23:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203572#M40210</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-11-02T23:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve when data getting duplicated twice in indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203573#M40211</link>
      <description>&lt;P&gt;@lguinn&lt;/P&gt;

&lt;P&gt;We did not touched any config files in forwarders.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 23:35:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203573#M40211</guid>
      <dc:creator>mpreddy</dc:creator>
      <dc:date>2016-11-02T23:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve when data getting duplicated twice in indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203574#M40212</link>
      <description>&lt;P&gt;are the duplicate events coming from the same bucket or different buckets? you can isolate one of the duplicate events, and then check with bucket+splunk_server the event and its duplicates are being returned from&lt;/P&gt;

&lt;P&gt;"some_dup_event | eval bkt=_bkt | fields + bkt,splunk_server"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:38:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203574#M40212</guid>
      <dc:creator>dxu_splunk</dc:creator>
      <dc:date>2020-09-29T11:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve when data getting duplicated twice in indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203575#M40213</link>
      <description>&lt;P&gt;Seems like an issue from 6.3.x upgrade to newer version after 6.4.x would fix the issue. &lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2017 00:00:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203575#M40213</guid>
      <dc:creator>vasanthmss</dc:creator>
      <dc:date>2017-02-02T00:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve when data getting duplicated twice in indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203576#M40214</link>
      <description>&lt;P&gt;I have the same problem and my version is Splunk Enterprise 6.5.3. Do you have an issue?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 15:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203576#M40214</guid>
      <dc:creator>erwan_raulet</dc:creator>
      <dc:date>2017-06-21T15:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve when data getting duplicated twice in indexers?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203577#M40215</link>
      <description>&lt;P&gt;I have same issue my data is getting doubled in indexers  each time a log is captured &lt;/P&gt;</description>
      <pubDate>Mon, 20 Jan 2020 13:28:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-when-data-getting-duplicated-twice-in-indexers/m-p/203577#M40215</guid>
      <dc:creator>sreekarnapu1109</dc:creator>
      <dc:date>2020-01-20T13:28:23Z</dc:date>
    </item>
  </channel>
</rss>

