Getting Data In

input monitor all entries double - how to debug?

micm
Explorer

Hi,

I am indexing a directory on a central syslog server. All entries in the index exist exactly two times with a difference in the indexing timestamp of two or three seconds for every pair of identical events.

I already checked that there are no symlinks and the files are not rotated.

[monitor:///var/log/remote]
disabled=false
whitelist=.*(ag|did)\d+_.+$
host_segment=4
sourcetype=syslog
index=messages

How can I continue debugging this problem? As those events never appear more than twice I assume that the recognition of where new syslog entries begin in the files works in general.

0 Karma
1 Solution

micm
Explorer

Sorry, stupid mistake.

I had a second outputs.conf on the forwarder that had the lb group and one member of the group explicitly as targets.

View solution in original post

0 Karma

micm
Explorer

Sorry, stupid mistake.

I had a second outputs.conf on the forwarder that had the lb group and one member of the group explicitly as targets.

0 Karma
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...