Getting Data In

HTTP input sending duplicate events?

snisaxena
Loves-to-Learn

I have configured HTTP inputs by creating HEC token in heavy forwarder.

I see duplicate events every time I test sending data via these HEC token. I have validated that source does not have duplicate events.

Even if I send a test event using curl command, it appears twice.

curl -k https://<endpoint>:8088/services/collector/event -H "Authorization: Splunk <HEC token>” -d '{"event": "This is a test event"}'

Please help find out why are there duplicate events and how can I fix it.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...