Splunk Enterprise

What could be causing Splunk Enterprise to re-index the same events every time a new one gets logged?

michaeler
Explorer

I recently took over as an admin for Splunk on one of my company's networks. We have 4 Forwarders and one enterprise instance. We recently updated our workstations and started getting large increases in events and exceeded our index by 8x everyday.

I recently monitored the data at different points in the day and realized every event is getting re-indexed every minute. I watched one time period grow from 2500 events to 250,000 by the end of the day. If i refreshed the search it would have an additional 1200 events every minute (roughly).

What could be causing Splunk to re-index the same events everytime a new one gets logged?

Labels (1)
0 Karma

thambisetty
Super Champion

can you provide inputs.conf.

————————————
If this helps, give a like below.
0 Karma

michaeler
Explorer

I'm not there and don't have it memorized but its something like this:

[WinEventLog://Security]
disabled = 0
start_from = newest
blacklist = 4648,7310
suppress_text = 1

[WinEventLog://Application]
disabled = 0
start_from = newest
blacklist = 4648,7310
suppress_text = 1

[WinEventLog://System]
disabled = 0
start_from = newest
blacklist = 4648,7310
suppress_text = 1

[perfmon]

disabled = 1

I've previously set "starts_from = oldest" and had the same issues.

0 Karma

michaeler
Explorer

Ignore the code numbers on the blacklist. I can't remember the specifics for each of those but I've blacklisted what contributes roughly 90% of all logs for each source.

0 Karma
Get Updates on the Splunk Community!

Security Highlights | November 2022 Newsletter

 November 2022 2022 Gartner Magic Quadrant for SIEM: Splunk Named a Leader for the 9th Year in a RowSplunk is ...

Platform Highlights | November 2022 Newsletter

 November 2022 Skill Up on Splunk with our New Builder Tech Talk SeriesCan you build it? Yes you can! *play ...

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...