Splunk Search

splunk showing 1 event 2 times in multi site cluster

pranay_adla
Explorer

We aren't supposed to see the same results from both sites. For a given event we should only see it coming from one site (whichever had the searchable copy). It almost appears that Splunk is giving a result from each site.

What might be the issue here and how to resolve

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Are you sure the event wasn't ingested twice?  

---
If this reply helps you, Karma would be appreciated.
0 Karma

pranay_adla
Explorer

All of sudden all indexes in are have same issue but not all the events only few events showing duplicates.
Not an issue with ingestion twice

0 Karma
Get Updates on the Splunk Community!

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

The Great Resilience Quest: 9th Leaderboard Update

The ninth leaderboard update (11.9-11.22) for The Great Resilience Quest is out >> Kudos to all the ...