Getting Data In

How to avoid duplicate indexing from HTTP event collector and file

New Member

I have an application which send event to HTTP event collector and writes a backup log to disk.

Can I somehow configure Splunk to index a log file, incase HTTP endpoint will be unavailable?
How could I deduplicate the events?

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.