Hi,
I have 2 files with 1.log and 1.log.gz but they have exact same data. I see that indexer indexes both somehow.
firstTime lastTime recentTime source totalCount type
1392760800 1392847199 1392847202 /20140219.log 9795685 sources
1392760800 1392847199 1393110875 /20140219.log.gz 9795685 sources
any idea to have only index 1 of the double data with different file names.!
You will want to use a whitelist in inputs.conf
[monitor:///your/path/to/monitor]
whitelist = \.log$
sourcetype = your_sourcetype
This will exclude anything that doesn't end in .log.
What does the monitor section for this input in your inputs.conf contain?