When I configure INGEST_EVAL to replace _raw with something else, it duplicates the event.
Splunk Enterprise Version 8.2.1
I found a workaround to circumvent this bug.
Because I notices that one of the duplicates has an indexed field "timestamp::none" and the other does not. With this I am routing only one of the to the nullQueue and keep the other.
View solution in original post