Getting Data In

Events are indexed multiple times

evelenke
Contributor

Hi Splunkers,

we have a lot of files\folders inputs (established on heavy forwarders) and during the last days we've observed substantial increase in indexing volume (even license violation). Analysis reveals re-indexing of events for particular source (4 hosts of the same index and sourcetype) up to 300-700 times during last 2 days (using stats count by _raw) after changing the name of a sourcetype (custom IIS type)
What may cause this behavior and how can I fix it?
Splunk Enterprise 7.2.5

Update: there's the following error: "IndexWriter - The index processor has paused data flow. Too many tsidx files in idx=myindex bucket="$path$/$myindex$/db/hot_v1_714" , waiting for the splunk-optimize indexing helper to catch up merging them. Ensure reasonable disk space is available, and that I/O write throughput is not compromised.

0 Karma

tiagofbmm
Influencer

Is someone having fun cleaning up the fishbucket ?

0 Karma

evelenke
Contributor

If only Splunk does

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...