<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: duplicate data indexing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-data-indexing/m-p/461778#M99495</link>
    <description>&lt;P&gt;Please add your outputs.conf to this post.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2019 20:32:45 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2019-08-26T20:32:45Z</dc:date>
    <item>
      <title>duplicate data indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-data-indexing/m-p/461776#M99493</link>
      <description>&lt;P&gt;i see duplicate data getting indexed.its impacting license. can you please suggest how i can fix this.below is the monitoring .&lt;BR /&gt;
[monitor:///incoming/XXXXX/XXXX/XXXXX.gz]&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;H1&gt;whitelist = ..gz&lt;/H1&gt;

&lt;P&gt;index = XXXXX&lt;BR /&gt;
sourcetype = XXXX&lt;BR /&gt;
EVENT_BREAK_ENABLE=true&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-data-indexing/m-p/461776#M99493</guid>
      <dc:creator>shivanandbm</dc:creator>
      <dc:date>2020-09-30T01:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: duplicate data indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-data-indexing/m-p/461777#M99494</link>
      <description>&lt;P&gt;Hi, How many indexers you have and how you are confirming that the duplicate data is ingesting. If those duplicate logs are from same application servers and exactly same in format, Splunk is smart enough to drop the duplicate logs.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 20:29:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-data-indexing/m-p/461777#M99494</guid>
      <dc:creator>sathwikr076</dc:creator>
      <dc:date>2019-08-26T20:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: duplicate data indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/duplicate-data-indexing/m-p/461778#M99495</link>
      <description>&lt;P&gt;Please add your outputs.conf to this post.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 20:32:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/duplicate-data-indexing/m-p/461778#M99495</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-08-26T20:32:45Z</dc:date>
    </item>
  </channel>
</rss>

