<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are multiple of the same events and values from a single source file being indexed in Splunk? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200202#M58022</link>
    <description>&lt;P&gt;Whether we add newest at end or beginning, but after parsing it should display logs properly as separate evnets and only three events. Why multiple?&lt;/P&gt;

&lt;P&gt;Have you resolved your issue?&lt;/P&gt;</description>
    <pubDate>Mon, 31 Aug 2015 04:30:57 GMT</pubDate>
    <dc:creator>pushpasinghal</dc:creator>
    <dc:date>2015-08-31T04:30:57Z</dc:date>
    <item>
      <title>Why are multiple of the same events and values from a single source file being indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200200#M58020</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;

&lt;P&gt;I have a source file like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;{"ts":"08 26 2015 13:05:41.374","th":"http-bio-8080-exec-1", "level":"DEBUG","logger":"org.apache.cxf.jaxrs.utils.JAXRSUtils","msg":"No resource class match for com.kronos.sdm.impl.rest.services.publishHistory.PublishHistoryServiceImpl, request path : \/usermanagement\/v1\/environments"  }
{"ts":"08 26 2015 13:05:41.374","th":"http-bio-8080-exec-1", "level":"DEBUG","logger":"org.apache.cxf.jaxrs.utils.JAXRSUtils","msg":"No resource class match for com.kronos.sdm.impl.rest.services.setupItem.SetupItemServiceImpl, request path : \/usermanagement\/v1\/environments"  }
{"ts":"08 26 2015 13:05:41.375","th":"http-bio-8080-exec-1", "level":"DEBUG","logger":"org.apache.cxf.jaxrs.utils.JAXRSUtils","msg":"No resource class match for com.wordnik.swagger.jaxrs.listing.ApiListingResourceJSON, request path : \/usermanagement\/v1\/environments"  }
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But while doing a Splunk search, it's showing 8000+ of the same events with same values. As per my observation, while storing data in the index, it is storing it multiple times.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2015 12:11:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200200#M58020</guid>
      <dc:creator>pushpasinghal</dc:creator>
      <dc:date>2015-08-30T12:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Why are multiple of the same events and values from a single source file being indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200201#M58021</link>
      <description>&lt;P&gt;how is the logfile created? Is the newest log at the end of the file?&lt;BR /&gt;
I had once the same problem, when a Logfile created new Logs always at the first line.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2015 17:17:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200201#M58021</guid>
      <dc:creator>lukas_loder</dc:creator>
      <dc:date>2015-08-30T17:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Why are multiple of the same events and values from a single source file being indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200202#M58022</link>
      <description>&lt;P&gt;Whether we add newest at end or beginning, but after parsing it should display logs properly as separate evnets and only three events. Why multiple?&lt;/P&gt;

&lt;P&gt;Have you resolved your issue?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 04:30:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200202#M58022</guid>
      <dc:creator>pushpasinghal</dc:creator>
      <dc:date>2015-08-31T04:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: Why are multiple of the same events and values from a single source file being indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200203#M58023</link>
      <description>&lt;P&gt;have you checked the logfile on the sourcesystem?&lt;BR /&gt;
$Splunk$\var\log\splunk\splunkd.log&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 08:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200203#M58023</guid>
      <dc:creator>lukas_loder</dc:creator>
      <dc:date>2015-08-31T08:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why are multiple of the same events and values from a single source file being indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200204#M58024</link>
      <description>&lt;P&gt;yes..but this is not any error so what shall i search in for?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 08:52:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200204#M58024</guid>
      <dc:creator>pushpasinghal</dc:creator>
      <dc:date>2015-08-31T08:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Why are multiple of the same events and values from a single source file being indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200205#M58025</link>
      <description>&lt;P&gt;something like this&lt;BR /&gt;
WatchedFile - Will begin reading at offset=0 for file=&lt;/P&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;P&gt;WatchedFile - Checksum for seekptr didn't match, will re-read entire file=&lt;/P&gt;

&lt;P&gt;those aren't Errors. It's are "INFO"&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 08:57:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200205#M58025</guid>
      <dc:creator>lukas_loder</dc:creator>
      <dc:date>2015-08-31T08:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Why are multiple of the same events and values from a single source file being indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200206#M58026</link>
      <description>&lt;P&gt;There are these type of lines but not for my file that is to be indexed. Its for splunk log files&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 09:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200206#M58026</guid>
      <dc:creator>pushpasinghal</dc:creator>
      <dc:date>2015-08-31T09:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why are multiple of the same events and values from a single source file being indexed in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200207#M58027</link>
      <description>&lt;P&gt;sorry.. but I don't have any further idea...&lt;BR /&gt;
may go and check this Website&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.4/Data/Editinputs.conf"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.4/Data/Editinputs.conf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And things like&lt;BR /&gt;
followTail = &lt;BR /&gt;
recursive = &lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2015 09:05:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-are-multiple-of-the-same-events-and-values-from-a-single/m-p/200207#M58027</guid>
      <dc:creator>lukas_loder</dc:creator>
      <dc:date>2015-08-31T09:05:02Z</dc:date>
    </item>
  </channel>
</rss>

