Getting Data In

input monitor all entries double - how to debug?

micm
Explorer

Hi,

I am indexing a directory on a central syslog server. All entries in the index exist exactly two times with a difference in the indexing timestamp of two or three seconds for every pair of identical events.

I already checked that there are no symlinks and the files are not rotated.

[monitor:///var/log/remote]
disabled=false
whitelist=.*(ag|did)\d+_.+$
host_segment=4
sourcetype=syslog
index=messages

How can I continue debugging this problem? As those events never appear more than twice I assume that the recognition of where new syslog entries begin in the files works in general.

0 Karma
1 Solution

micm
Explorer

Sorry, stupid mistake.

I had a second outputs.conf on the forwarder that had the lb group and one member of the group explicitly as targets.

View solution in original post

0 Karma

micm
Explorer

Sorry, stupid mistake.

I had a second outputs.conf on the forwarder that had the lb group and one member of the group explicitly as targets.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...