Getting Data In

Splunk File Monitoring

mohsplunking
Path Finder

Hello Splunkers,

I have a question around Monitoring a same File from different server, The situation is Server1, Server,2,Server3 is connected to the same NFS where log file abc.log is , now Splunk universal forwarder is installed on all these servers and in the inputs.conf has a monitoring stanza to monitor log file /a/b/c/abc.log, what are the options here to avoid duplication on forwarding/indexing.

Please advise,

Thank !

Moh..

Labels (4)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

If I understand you correctly, you have a file on share exported from an NFS server. This share is mounted on several client machines and contents of the files from that share are being monitored on those machines.

There is no deduplication functionality for ingested data in Splunk (it would be very difficult to do something that would work efficiently and didn't have too many limitations). Especially if the data comes from multiple different sources.

Your best bet would be to make sure you monitor the file only once (possibly from the server itself, not from the client machines).

0 Karma

isoutamo
SplunkTrust
SplunkTrust

It's exactly like @PickleRick said. Splunk didn't offer any official method to do this kind of deduplication. Then best option is install UF into this nfs server and use it as collecting those. 

Then depending what your actually environment is (there are several possibilities which come into my mind) there could be some other ways to manage it.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...