<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk_TA_aws duplicated events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513218#M87037</link>
    <description>&lt;P&gt;You could say its problem/issue with TA if you are observing same behavior for all the inputs you have created using the TA.&lt;/P&gt;&lt;P&gt;I would recommend creating a new input which you don’t think the events of this input are not duplicated with other input in AWS.&lt;/P&gt;</description>
    <pubDate>Sun, 09 Aug 2020 16:44:48 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-08-09T16:44:48Z</dc:date>
    <item>
      <title>Splunk_TA_aws duplicated events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513201#M87032</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have&amp;nbsp;Splunk_TA_aws installed on the heave forwarder&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the input are&amp;nbsp;&lt;/P&gt;&lt;P&gt;[aws_s3://aws_dome9_logs_amdocsdome9logs]&lt;BR /&gt;aws_account = IS account&lt;BR /&gt;bucket_name = amdocsdome9logs&lt;BR /&gt;character_set = auto&lt;BR /&gt;ct_blacklist = ^$&lt;BR /&gt;host_name = s3.amazonaws.com&lt;BR /&gt;index = aws_dome9_logs&lt;BR /&gt;initial_scan_datetime = 2018-01-01T21:54:23-0700&lt;BR /&gt;interval = 30&lt;BR /&gt;is_secure = True&lt;BR /&gt;max_items = 100000&lt;BR /&gt;max_retries = 3&lt;BR /&gt;recursion_depth = -1&lt;BR /&gt;sourcetype = _json_current_time&lt;/P&gt;&lt;P&gt;[aws_s3://aws_dome9_logs_amdocsdome9remediationlogs]&lt;BR /&gt;aws_account = IS account&lt;BR /&gt;bucket_name = amdocsdome9remediationlogs&lt;BR /&gt;character_set = auto&lt;BR /&gt;ct_blacklist = ^$&lt;BR /&gt;host_name = s3.amazonaws.com&lt;BR /&gt;index = aws_dome9_logs&lt;BR /&gt;initial_scan_datetime = 2018-01-01T21:54:23-0700&lt;BR /&gt;interval = 30&lt;BR /&gt;is_secure = True&lt;BR /&gt;max_items = 100000&lt;BR /&gt;max_retries = 3&lt;BR /&gt;recursion_depth = -1&lt;BR /&gt;sourcetype = _json_current_time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what can be the reason the same event if indexed twice (day after day )&amp;nbsp;&lt;BR /&gt;according to the json file diff the files are identical&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 13:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513201#M87032</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2020-08-09T13:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_aws duplicated events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513207#M87035</link>
      <description>Are you saying you have the same file in two places and Splunk is indexing it from both places? If so, that is normal. Splunk is merely doing what it was asked to do. It doesn't know the same data is already indexed.&lt;BR /&gt;The solution is to not put the same data in two places that are monitored by Splunk.</description>
      <pubDate>Sun, 09 Aug 2020 16:01:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513207#M87035</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-09T16:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_aws duplicated events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513218#M87037</link>
      <description>&lt;P&gt;You could say its problem/issue with TA if you are observing same behavior for all the inputs you have created using the TA.&lt;/P&gt;&lt;P&gt;I would recommend creating a new input which you don’t think the events of this input are not duplicated with other input in AWS.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 16:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513218#M87037</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-09T16:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_aws duplicated events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513275#M87049</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am checking now with Dome9 team&amp;nbsp;&lt;/P&gt;&lt;P&gt;will update&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 09:03:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-TA-aws-duplicated-events/m-p/513275#M87049</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2020-08-10T09:03:53Z</dc:date>
    </item>
  </channel>
</rss>

