Splunk Enterprise

Duplicate events

VijaySrrie
Builder

Hi Team,

Getting Duplicate events during Index time

Log ingestion method - UF

What would be done to stop duplicate events?

Labels (2)
0 Karma

VijaySrrie
Builder

All Ok with inputs and outputs, issue is only with one source.
New servers which are getting migrated are sending duplicate logs.

Need a workaround for that.

0 Karma

venkatasri
SplunkTrust
SplunkTrust

@VijaySrrie  If you know the old host which is sending duplicates you can send them to nullQueue (you have to deploy this change on HF). There will be only single source new host hence you can avoid duplicates.

venkatasri
SplunkTrust
SplunkTrust

@VijaySrrie 

how the inputs.conf looks like and does outputs.conf  any different than default settings?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...