<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there any way to avoid syslog-ng duplicate data? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Is-there-any-way-to-avoid-syslog-ng-duplicate-data/m-p/604385#M11692</link>
    <description>&lt;P&gt;I have syslog-ng configuration that started duplicating the events after the Linux box reboot&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there any way to avoid it&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;the are 2 heavy forwarders defined for the same load balancer and only 1 is duplicating the events in the syslog files created&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[root@ilissplfwd07 syslog-ng]# cat syslog-ng.conf&lt;BR /&gt;@version:3.5&lt;BR /&gt;@include "scl.conf"&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;# syslog-ng configuration file.&lt;BR /&gt;#&lt;BR /&gt;# This should behave pretty much like the original syslog on RedHat. But&lt;BR /&gt;# it could be configured a lot smarter.&lt;BR /&gt;#&lt;BR /&gt;# See syslog-ng(8) and syslog-ng.conf(5) for more information.&lt;BR /&gt;#&lt;BR /&gt;# Note: it also sources additional configuration files (*.conf)&lt;BR /&gt;# located in /etc/syslog-ng/conf.d/&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;options {&lt;BR /&gt;flush_lines (0);&lt;BR /&gt;time_reopen (10);&lt;BR /&gt;log_fifo_size (1000);&lt;BR /&gt;chain_hostnames (off);&lt;BR /&gt;use_dns (no);&lt;BR /&gt;use_fqdn (no);&lt;BR /&gt;owner("splunk");&lt;BR /&gt;group("splunk");&lt;BR /&gt;dir-owner("splunk");&lt;BR /&gt;dir-group("splunk");&lt;BR /&gt;create_dirs (yes);&lt;BR /&gt;keep_hostname (yes);&lt;BR /&gt;};&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;## add Default 514 udp/tcp &amp;amp; Filtered based don't modify below line #############################################&lt;BR /&gt;# Syslog 514&lt;BR /&gt;#source s_syslog { udp(port(514)); tcp(port(514) keep-alive(yes)); };&lt;BR /&gt;source s_syslog518 { udp(port(518)); };&lt;BR /&gt;source s_syslog1513 { tcp(port(1513) keep-alive(yes)); };&lt;BR /&gt;source s_syslog1514 { tcp(port(1514) keep-alive(yes)); };&lt;BR /&gt;source s_syslog1515 { tcp(port(1515) keep-alive(yes)); };&lt;BR /&gt;source s_syslog1516 { tcp(port(1516) keep-alive(yes)); };&lt;/P&gt;
&lt;P&gt;destination d_1513 { file("/splunksyslog/port1513/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog1513); destination(d_1513); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination d_1514 { file("/splunksyslog/port1514/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog1514); destination(d_1514); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination d_1515 { file("/splunksyslog/port1515/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog1515); destination(d_1515); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination d_1516 { file("/splunksyslog/port1516/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog1516); destination(d_1516); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;# destination d_catch { file("/splunksyslog/catch/$HOST/$YEAR-$MONTH-$DAY-$HOUR-catch.log");};&lt;/P&gt;
&lt;P&gt;# log { source(s_syslog); destination(d_catch); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination d_518 { file("/splunksyslog/port518/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog518); destination(d_518); };&lt;BR /&gt;@include "/etc/syslog-ng/conf.d/*.conf"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2022 18:20:12 GMT</pubDate>
    <dc:creator>rayar</dc:creator>
    <dc:date>2022-07-05T18:20:12Z</dc:date>
    <item>
      <title>Is there any way to avoid syslog-ng duplicate data?</title>
      <link>https://community.splunk.com/t5/Installation/Is-there-any-way-to-avoid-syslog-ng-duplicate-data/m-p/604385#M11692</link>
      <description>&lt;P&gt;I have syslog-ng configuration that started duplicating the events after the Linux box reboot&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there any way to avoid it&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;the are 2 heavy forwarders defined for the same load balancer and only 1 is duplicating the events in the syslog files created&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[root@ilissplfwd07 syslog-ng]# cat syslog-ng.conf&lt;BR /&gt;@version:3.5&lt;BR /&gt;@include "scl.conf"&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;# syslog-ng configuration file.&lt;BR /&gt;#&lt;BR /&gt;# This should behave pretty much like the original syslog on RedHat. But&lt;BR /&gt;# it could be configured a lot smarter.&lt;BR /&gt;#&lt;BR /&gt;# See syslog-ng(8) and syslog-ng.conf(5) for more information.&lt;BR /&gt;#&lt;BR /&gt;# Note: it also sources additional configuration files (*.conf)&lt;BR /&gt;# located in /etc/syslog-ng/conf.d/&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;options {&lt;BR /&gt;flush_lines (0);&lt;BR /&gt;time_reopen (10);&lt;BR /&gt;log_fifo_size (1000);&lt;BR /&gt;chain_hostnames (off);&lt;BR /&gt;use_dns (no);&lt;BR /&gt;use_fqdn (no);&lt;BR /&gt;owner("splunk");&lt;BR /&gt;group("splunk");&lt;BR /&gt;dir-owner("splunk");&lt;BR /&gt;dir-group("splunk");&lt;BR /&gt;create_dirs (yes);&lt;BR /&gt;keep_hostname (yes);&lt;BR /&gt;};&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;## add Default 514 udp/tcp &amp;amp; Filtered based don't modify below line #############################################&lt;BR /&gt;# Syslog 514&lt;BR /&gt;#source s_syslog { udp(port(514)); tcp(port(514) keep-alive(yes)); };&lt;BR /&gt;source s_syslog518 { udp(port(518)); };&lt;BR /&gt;source s_syslog1513 { tcp(port(1513) keep-alive(yes)); };&lt;BR /&gt;source s_syslog1514 { tcp(port(1514) keep-alive(yes)); };&lt;BR /&gt;source s_syslog1515 { tcp(port(1515) keep-alive(yes)); };&lt;BR /&gt;source s_syslog1516 { tcp(port(1516) keep-alive(yes)); };&lt;/P&gt;
&lt;P&gt;destination d_1513 { file("/splunksyslog/port1513/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog1513); destination(d_1513); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination d_1514 { file("/splunksyslog/port1514/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog1514); destination(d_1514); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination d_1515 { file("/splunksyslog/port1515/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog1515); destination(d_1515); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination d_1516 { file("/splunksyslog/port1516/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog1516); destination(d_1516); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;# destination d_catch { file("/splunksyslog/catch/$HOST/$YEAR-$MONTH-$DAY-$HOUR-catch.log");};&lt;/P&gt;
&lt;P&gt;# log { source(s_syslog); destination(d_catch); };&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;destination d_518 { file("/splunksyslog/port518/$HOST/syslog_$FACILITY_$YEAR-$MONTH-$DAY-$HOUR-$(/ $MIN 1).log");};&lt;/P&gt;
&lt;P&gt;log { source(s_syslog518); destination(d_518); };&lt;BR /&gt;@include "/etc/syslog-ng/conf.d/*.conf"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 18:20:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Is-there-any-way-to-avoid-syslog-ng-duplicate-data/m-p/604385#M11692</guid>
      <dc:creator>rayar</dc:creator>
      <dc:date>2022-07-05T18:20:12Z</dc:date>
    </item>
  </channel>
</rss>

