I have a source logfile /var/splunk/log/user.log.I am sending the data from UF--->HF-->Indexer. And I am seeing the data is getting duplicated. Data is getting duplicated only from this source. I checked splunkd.log and got the below error:-
WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file
Please let me know what can be done to fix the issue?