Hi,
Had a customer who was using a TA to get data from Cisco ESA into Splunk. They wondered whether or not it was possible to get multiline-events into Splunk from different data sources at different times and not have duplicate events as a result in Splunk.
Any help on this issue would be greatly appreciated.
If done correctly, multi-line events will be indexed as a single event and duplication is an unlikely problem.