Getting Data In

Why are we seeing duplicate data coming from a Splunk Enterprise forwarder to an external syslog server?

jppham
New Member

I am seeing duplicate events coming from SPLUNK to our external logger.
external syslog server is 10.1.1.25

It appears there are duplicate specs in different stanzas below. Could this be the cause of the duplicate data
we are seeing?
[syslog:Everything]
[syslog:Logger]

OUTPUTS

[syslog]
defaultGroup =

[syslog:Everything]
disabled = false
timestampformat = %b %e %H:%M:%S
server = 10.1.1.25:514

[syslog:Logger]
disabled = false
timestampformat = %b %e %H:%M:%S
server = 10.1.1.25:514

[tcpout]
maxQueueSize = 500KB
forwardedindex.0.whitelist = .*
forwardedindex.1.blacklist = _.*
forwardedindex.2.whitelist = _audit
forwardedindex.filter.disable = false
indexAndForward = false
autoLBFrequency = 30
blockOnCloning = true
compressed = false
disabled = false
dropClonedEventsOnQueueFull = 5
dropEventsOnQueueFull = -1
heartbeatFrequency = 30
maxFailuresPerInterval = 2
secsInFailureInterval = 1
maxConnectionsPerIndexer = 2
forceTimebasedAutoLB = false
sendCookedData = true
connectionTimeout = 20
readTimeout = 300
writeTimeout = 300
useACK = false

defaultGroup=nowhere

0 Karma

Richfez
SplunkTrust
SplunkTrust

Have you tried commenting one of those two stanzas out, restarting Splunk and seeing what happens?

0 Karma

jppham
New Member

My first thought was to comment out the first stanza, but I wasn't sure if this could be the cause.
I will probably try that.

thanks for the suggestion.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...