I suspect that I may have duplicate events indexed by Splunk after the splunk DB_connect_app upgrade from 2.4 version to 3.1.3 version. The cause may be my originating files having dupes OR my Splunk configuration may be indexing some events twice or more times.
To be sure, what search can I run to find all my duplicate events currently within my Splunk index?