- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Multiline events ingested by Splunk at different times: How to not have duplicate events?
malmoore

Splunk Employee
09-10-2020
12:31 PM
Hi,
Had a customer who was using a TA to get data from Cisco ESA into Splunk. They wondered whether or not it was possible to get multiline-events into Splunk from different data sources at different times and not have duplicate events as a result in Splunk.
Any help on this issue would be greatly appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

richgalloway

SplunkTrust
09-10-2020
02:00 PM
If done correctly, multi-line events will be indexed as a single event and duplication is an unlikely problem.
---
If this reply helps you, Karma would be appreciated.
If this reply helps you, Karma would be appreciated.
