Hi stwong,
tscollect is a stupid command: it doesn't check if the events was already ingested, so you have to configure you time periods without overlap otherwise you'll have duplicate events.
If you cannot do this, you have to insert in your tscollect search also a condition on indextime, discarding the ones with indextime < the time of last schedule (e.g. if scheduling is every hour, -h@h).
I asked to splunk to insert this check in the future developments and I hope!
In addition it isn't possible to delete some events from a tsidx index, you can only delete the entire index.
You can delete the tsidx index phisically deleting files that you can find by default in $SPLUNK_HOME/var/lib/splunk/tsidxstats/
Bye.
Giuseppe
... View more