Splunk shows duplicate events in search results when there are no duplicates in the source file.
How does the data get from the source file to Splunk? If there are multiple readers then there could be duplicate data.
Hi
or is this data structured like json and you have both INDEXED_EXTRACTION and KV_MODE defined?
r. Ismo