Splunk Search

Issues with Rollup Events

SplunkDash
Motivator

Hello,

I have a Roll Up events. One file created every month and new events added up every day within that file. How would I avoid duplicate ingestion (or avoid same events to be indexed twice) for the same events as SPLUNK is using the same file to read and ingest? Any help will be highly appreciated. Thank you.

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkDash ,

if you don't use crcSalt = <SOURCE> option, Splunk recognizes already indexed events and it doesn't index them twice. even if they come from files with different filenames.

The only situation where the same logs from different files are indexed is using the above option in inputs.conf.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkDash ,

if you don't use crcSalt = <SOURCE> option, Splunk recognizes already indexed events and it doesn't index them twice. even if they come from files with different filenames.

The only situation where the same logs from different files are indexed is using the above option in inputs.conf.

Ciao.

Giuseppe

SplunkDash
Motivator

Hello @gcusello 

I posted a new question here (in following link), would it be possible to have your recommendation when you get a chance, thank you so much.

Re: Field Extraction -Key/ Value Pairs with Specia... - Splunk Community

 

 

Tags (1)
0 Karma

SplunkDash
Motivator

Hello @gcusello,

Thank you so much for your respond, it's answered major part of my question. But, other part of my question, new records/events added everyday within the same file (like added at the end of the same file)), how SPLUNK will ingest/treat those new events/records as those new events will be within the same file?

0 Karma

yeahnah
Motivator

Hi @SplunkDash 

I've read your question a couple of times but I still do not really understand what you are asking.  Please expand on the situation you describe and provide examples.

If it is just that a file is renamed each month in a monitored folder, then this is OK, as Splunk does not track files by only their filename.  It also check sums the first 256 bytes of the head of the file, so if it is renamed then it knows it has already ingested it. 

Anyway, best to describe your concern better so the correct answer can be provided. 

SplunkDash
Motivator

Hello @yeahnah 

Thank you so much for your quick response. My question was, new records/events added everyday within the same file (like at the end of the same file)), how SPLUNK will ingest those new events/records? 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Customer Survey!

If you use Splunk Observability Cloud, we invite you to share your valuable insights with us through a brief ...

Happy CX Day, Splunk Community!

Happy CX Day, Splunk Community! CX stands for Customer Experience, and today, October 3rd, is CX Day — a ...

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...