<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to identify a raw events splunk instance origin in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-identify-a-raw-events-splunk-instance-origin/m-p/86604#M22082</link>
    <description>&lt;P&gt;Well, it seems that you can't indentify the source splunk instance.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Oct 2012 22:52:56 GMT</pubDate>
    <dc:creator>Lucas_K</dc:creator>
    <dc:date>2012-10-15T22:52:56Z</dc:date>
    <item>
      <title>How to identify a raw events splunk instance origin</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-identify-a-raw-events-splunk-instance-origin/m-p/86603#M22081</link>
      <description>&lt;P&gt;Does anyone know how to identify the splunk instance from which a raw event was forwarded?&lt;BR /&gt;
Note: this could either be a heavy or a universal forwarder.&lt;/P&gt;

&lt;P&gt;I might have expected to see a field that had this information but I can't see to find it.&lt;/P&gt;

&lt;P&gt;I am looking to prove where specific already indexed messages came from.&lt;/P&gt;

&lt;P&gt;The issue I have is that I believe a second forwarder instance was accidentally started on the same machine and it that forwarded the same events to the same index. We converted from a heavy to a universal but the heavy was restarted during an OS reboot (forgot to run the boot-start command i expect).&lt;/P&gt;

&lt;P&gt;A "| dedup _raw" fixes it for future searches but I am just interested in how I could specifically identify the source. Ideally so I can filter these results with a |delete also &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 05:32:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-identify-a-raw-events-splunk-instance-origin/m-p/86603#M22081</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2012-10-11T05:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to identify a raw events splunk instance origin</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-identify-a-raw-events-splunk-instance-origin/m-p/86604#M22082</link>
      <description>&lt;P&gt;Well, it seems that you can't indentify the source splunk instance.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2012 22:52:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-identify-a-raw-events-splunk-instance-origin/m-p/86604#M22082</guid>
      <dc:creator>Lucas_K</dc:creator>
      <dc:date>2012-10-15T22:52:56Z</dc:date>
    </item>
  </channel>
</rss>

