Getting Data In

How to avoid duplicate indexing from HTTP event collector and file

uniqueusername1
New Member

I have an application which send event to HTTP event collector and writes a backup log to disk.

Can I somehow configure Splunk to index a log file, incase HTTP endpoint will be unavailable?
How could I deduplicate the events?

0 Karma
Get Updates on the Splunk Community!

From Alert to Resolution: How Splunk Observability Helps SREs Navigate Critical ...

It's 3:17 AM, and your phone buzzes with an urgent alert. Wire transfer processing times have spiked, and ...

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...