Splunk Enterprise

What could be causing Splunk Enterprise to re-index the same events every time a new one gets logged?

michaeler
Communicator

I recently took over as an admin for Splunk on one of my company's networks. We have 4 Forwarders and one enterprise instance. We recently updated our workstations and started getting large increases in events and exceeded our index by 8x everyday.

I recently monitored the data at different points in the day and realized every event is getting re-indexed every minute. I watched one time period grow from 2500 events to 250,000 by the end of the day. If i refreshed the search it would have an additional 1200 events every minute (roughly).

What could be causing Splunk to re-index the same events everytime a new one gets logged?

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

can you provide inputs.conf.

————————————
If this helps, give a like below.
0 Karma

michaeler
Communicator

I'm not there and don't have it memorized but its something like this:

[WinEventLog://Security]
disabled = 0
start_from = newest
blacklist = 4648,7310
suppress_text = 1

[WinEventLog://Application]
disabled = 0
start_from = newest
blacklist = 4648,7310
suppress_text = 1

[WinEventLog://System]
disabled = 0
start_from = newest
blacklist = 4648,7310
suppress_text = 1

[perfmon]

disabled = 1

I've previously set "starts_from = oldest" and had the same issues.

0 Karma

michaeler
Communicator

Ignore the code numbers on the blacklist. I can't remember the specifics for each of those but I've blacklisted what contributes roughly 90% of all logs for each source.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...