I have a clustered enviroment. But still getting duplicate events in splunk -ITSI indexes. Please give some recommendation .
Both SH and Indexer cluster is there. I have configured Splunk -ITSI with servicenow , after configuring we found that duplicate events are coming in itsi_tracked_alerts and itsi_grouped_alerts indexes
How is the ServiceNow data getting in to Splunk? I suspect inputs are running in more than one location, which is causing the duplicate data.