Monitoring Splunk

How to confirm does my index have duplicate events?



When I execute this search

index=foo | stats count by _raw, sourcetype, source, host | where count>1

, I'm able to observe events with counts higher than 1. However, I'm uncertain if these events are being duplicated. Is there an alternative search method I can use to verify whether these events are being double-ingested?


Labels (2)
0 Karma


Hi @AL3Z,

if you have results to your search, it should be sure that you have duplicated events.

You can analyze your data to undertand where these duplicates come from and if there's the possibility of duplication.



0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...