Getting Data In

will duplicate entries of monitor statements in inputs.conf coz Logs to be indexed twice?

sarnagar
Contributor

In our inputs there are wildcard entries for directories and I recently noticed there were duplicate entries for the same logfile.
Will that index the logs twice OR does Splunk take care of this and how?

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi sarnagar,
there isn't any duplications: if you address twice the same file, it will be indexed only one time.

You must take care when you have duplicated inputs if you set different indexes or sourcetypes because the log will be read only one time and assigned only to one index or sourcetype.

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...

GA: S3 Promote for Historical Data Ingestion in Splunk Cloud

Ingest Historical S3 Data On-Demand: Announcing the General Availability of S3 Promote We’re excited to share ...