<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are there duplicated Windows Security Logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448341#M95428</link>
    <description>&lt;P&gt;no this option is&lt;BR /&gt;
useACK = false&lt;/P&gt;

&lt;P&gt;should I change?&lt;/P&gt;

&lt;P&gt;İf I change this option , Do I have a log loss?&lt;BR /&gt;
if option is true , wait a 7mb logs, ı think is very long ? &lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2019 13:54:14 GMT</pubDate>
    <dc:creator>burakatabay</dc:creator>
    <dc:date>2019-03-18T13:54:14Z</dc:date>
    <item>
      <title>Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448339#M95426</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
My problem is duplicated windows security logs. 2 or more log same as each other.&lt;/P&gt;

&lt;H2&gt;why do that ? &lt;/H2&gt;

&lt;PRE&gt;&lt;CODE&gt;03/18/2019 10:53:50 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=TestClient.kvp
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=21040
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
    Security ID:        NT AUTHORITY\SYSTEM
    Account Name:       TestClient$
    Account Domain:     KVP
    Logon ID:       0x3E7

Group:
    Security ID:        BUILTIN\Administrators
    Group Name:     Administrators
    Group Domain:       Builtin

Process Information:
    Process ID:     0x46c
    Process Name:       C:\Windows\System32\VSSVC.exe

03/18/2019 10:53:50 AM
LogName=Security
SourceName=Microsoft Windows security auditing.
EventCode=4799
EventType=0
Type=Information
ComputerName=TestClient.kvp
TaskCategory=Security Group Management
OpCode=Info
RecordNumber=21040
Keywords=Audit Success
Message=A security-enabled local group membership was enumerated.

Subject:
    Security ID:        NT AUTHORITY\SYSTEM
    Account Name:       TestClient$
    Account Domain:     KVP
    Logon ID:       0x3E7

Group:
    Security ID:        BUILTIN\Administrators
    Group Name:     Administrators
    Group Domain:       Builtin

Process Information:
    Process ID:     0x46c
    Process Name:       C:\Windows\System32\VSSVC.exe
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;HR /&gt;</description>
      <pubDate>Mon, 18 Mar 2019 13:22:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448339#M95426</guid>
      <dc:creator>burakatabay</dc:creator>
      <dc:date>2019-03-18T13:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448340#M95427</link>
      <description>&lt;P&gt;Is this forwarded with useAck = true set on the forwarders outputs.conf?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 13:30:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448340#M95427</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-18T13:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448341#M95428</link>
      <description>&lt;P&gt;no this option is&lt;BR /&gt;
useACK = false&lt;/P&gt;

&lt;P&gt;should I change?&lt;/P&gt;

&lt;P&gt;İf I change this option , Do I have a log loss?&lt;BR /&gt;
if option is true , wait a 7mb logs, ı think is very long ? &lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 13:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448341#M95428</guid>
      <dc:creator>burakatabay</dc:creator>
      <dc:date>2019-03-18T13:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448342#M95429</link>
      <description>&lt;P&gt;No.&lt;/P&gt;

&lt;P&gt;Have you checked on the source windows server to see if the actual event is duplicated in event viewer?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 14:03:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448342#M95429</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-18T14:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448343#M95430</link>
      <description>&lt;P&gt;Yes I check the win event viewer. and logs it just one, &lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 14:09:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448343#M95430</guid>
      <dc:creator>burakatabay</dc:creator>
      <dc:date>2019-03-18T14:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448344#M95431</link>
      <description>&lt;P&gt;Can I find out what caused them by looking at the logs ? &lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 14:21:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448344#M95431</guid>
      <dc:creator>burakatabay</dc:creator>
      <dc:date>2019-03-18T14:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448345#M95432</link>
      <description>&lt;P&gt;try this:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[your search which finds duplicate events]|eval it=strftime(_indextime, "%Y-%m-%d %H:%M:%S.%N3"|table _time it host splunk_server Message&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Look at the two rows for your duplicated events - is the index time the same, are they from the same splunk_server?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 14:22:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448345#M95432</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-18T14:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448346#M95433</link>
      <description>&lt;P&gt;Sorry my wrong anser,&lt;BR /&gt;
ı check today and useAck = true&lt;BR /&gt;
and&lt;BR /&gt;
this query result is&lt;BR /&gt;
"_time",it,host,RecordNumber,"splunk_server"&lt;/P&gt;

&lt;P&gt;"2019-03-19T07:56:29.000+0300","2019-03-19 07:56:30.0000000003","TestClient",3778048,a4idx07p SameMessage&lt;/P&gt;

&lt;P&gt;"2019-03-19T07:56:29.000+0300","2019-03-19 07:56:55.0000000003","TestClient",3778048,a4idx06p SameMessage&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:43:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448346#M95433</guid>
      <dc:creator>burakatabay</dc:creator>
      <dc:date>2020-09-29T23:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448347#M95434</link>
      <description>&lt;P&gt;useAck is possibly the cause then. (With reference to the comments above)&lt;/P&gt;

&lt;P&gt;useAck ensures that you never 'loose' a message, but it can result in data duplication.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Forwarder/7.2.4/Forwarder/Protectagainstthelossofin-flightdata#How_lack_of_indexer_acknowledgment_can_cause_the_duplication_of_indexed_data"&gt;https://docs.splunk.com/Documentation/Forwarder/7.2.4/Forwarder/Protectagainstthelossofin-flightdata#How_lack_of_indexer_acknowledgment_can_cause_the_duplication_of_indexed_data&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 12:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448347#M95434</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-19T12:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448348#M95435</link>
      <description>&lt;P&gt;This suggests that useAck is the problem - You can see both events are generated at exactly the same time, but they are indexed 25 seconds apart, by different indexers.&lt;/P&gt;

&lt;P&gt;What likely happened is that the first message was received, but the indexer either did not ack the event in time (or it got lost on the network) so the forwarder resent it, resulting in the duplication.&lt;/P&gt;

&lt;P&gt;This is by design - useAck means no messages should ever get 'lost' but it can result in duplication - this is the tradeoff.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 13:26:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/448348#M95435</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-19T13:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Why are there duplicated Windows Security Logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/686290#M114434</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Forwarder's Operation :&lt;/STRONG&gt;&lt;BR /&gt;- After the forwarder sends a data block, it maintains a copy of the data in its wait queue until it receives an acknowledgment.&lt;BR /&gt;- Meanwhile, it continues to send additional blocks.&lt;BR /&gt;- If the forwarder doesn't get acknowledgment for a block within **300 seconds** (by default), it closes the connection.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Possibility of Data Duplication :&lt;/STRONG&gt;&lt;BR /&gt;- It is possible for the indexer to index the same data block twice.&lt;BR /&gt;- This can happen if there is a network problem that prevents an acknowledgment from reaching the forwarder.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Network Issues :&lt;/STRONG&gt;&lt;BR /&gt;- When the network goes down, the forwarder never receives the acknowledgment.&lt;BR /&gt;- When the network comes back up, the forwarder then resends the data block, which the indexer parses and writes as if it were new data.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Duplicate Warning Example :&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;10-18-2010 17:32:36.941 WARN TcpOutputProc - Possible duplication of events with&lt;BR /&gt;channel=source::/home/jkerai/splunk/current-install/etc/apps/sample_app&lt;BR /&gt;/logs/maillog.1|host::MrT|sendmail|, streamId=5941229245963076846, offset=131072&lt;BR /&gt;subOffset=219 on host=10.1.42.2:9992&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Note on useACK :&lt;/STRONG&gt;&lt;BR /&gt;- When `useACK` is enabled in the `outputs.conf` on forwarders, and there is either a network issue, indexer saturation (for example, pipeline blocks) or a replication problem, your Splunk platform deployment's indexers cannot respond to your deployment's forwarders acknowledgement.&lt;BR /&gt;- Based on your deployment environment, data duplication can occur.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.2.5/Forwarder/Protectagainstthelossofin-flightdata" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Forwarder/8.2.5/Forwarder/Protectagainstthelossofin-flightdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 09:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-are-there-duplicated-Windows-Security-Logs/m-p/686290#M114434</guid>
      <dc:creator>Pranav_Support</dc:creator>
      <dc:date>2024-05-03T09:37:09Z</dc:date>
    </item>
  </channel>
</rss>

