<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder resending event log data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304538#M57430</link>
    <description>&lt;P&gt;Is your forwarder resending event logs again? Has any specific activity was performed on your UF like version upgrade?&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2018 17:05:57 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2018-01-12T17:05:57Z</dc:date>
    <item>
      <title>Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304537#M57429</link>
      <description>&lt;P&gt;If the IP address for a host changes or if it gets a new GUID, would the forwarder resend the entire Windows event log?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 16:12:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304537#M57429</guid>
      <dc:creator>splunkjas1</dc:creator>
      <dc:date>2018-01-12T16:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304538#M57430</link>
      <description>&lt;P&gt;Is your forwarder resending event logs again? Has any specific activity was performed on your UF like version upgrade?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:05:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304538#M57430</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-12T17:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304539#M57431</link>
      <description>&lt;P&gt;The forwarders are resending event logs.  We upgraded them from 6.4.4 to 6.4.9.  Would the upgrade cause logs to be resent?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:08:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304539#M57431</guid>
      <dc:creator>splunkjas1</dc:creator>
      <dc:date>2018-01-12T17:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304540#M57432</link>
      <description>&lt;P&gt;It depends. &lt;BR /&gt;
If you uninstalled the old forwarder and then reinstalled the new one, it’s quite possible that it will re-read and send all the logs. &lt;/P&gt;

&lt;P&gt;If you upgraded the forwarder this should not occurr, even if the ip or guild changes. &lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:19:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304540#M57432</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-12T17:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304541#M57433</link>
      <description>&lt;P&gt;It should'nt. How did you do the upgrade (procedure)? Was it it inline with what this Splunk documentation suggests?&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/UpgradetheWindowsuniversalforwarder#Upgrade_a_single_forwarder_using_the_command_line"&gt;https://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/UpgradetheWindowsuniversalforwarder#Upgrade_a_single_forwarder_using_the_command_line&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:21:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304541#M57433</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-01-12T17:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304542#M57434</link>
      <description>&lt;P&gt;I asked the folks who performed the upgrade and they told me they do uninstall the 6.4.4 version before installing 6.4.9.  So that's probably what caused the logs to be resent, would you agree?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:24:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304542#M57434</guid>
      <dc:creator>splunkjas1</dc:creator>
      <dc:date>2018-01-12T17:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304543#M57435</link>
      <description>&lt;P&gt;Yes. In that case I would say it’s expected behaviour&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:27:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304543#M57435</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-12T17:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304544#M57436</link>
      <description>&lt;P&gt;Okay, thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:28:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304544#M57436</guid>
      <dc:creator>splunkjas1</dc:creator>
      <dc:date>2018-01-12T17:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304545#M57437</link>
      <description>&lt;P&gt;I converted my comment to an answer, so you can accept it if it helped &lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:32:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304545#M57437</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-12T17:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder resending event log data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304546#M57438</link>
      <description>&lt;P&gt;I noted “possible” because depending on your config, it may elect to only send evens which are older than x days, or in the case of windows events, only while the forwarder is running. Neither of these are default config, and have drawbacks. &lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 17:34:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-resending-event-log-data/m-p/304546#M57438</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2018-01-12T17:34:33Z</dc:date>
    </item>
  </channel>
</rss>

