Hi,
When I execute this search
index=foo | stats count by _raw, sourcetype, source, host | where count>1
, I'm able to observe events with counts higher than 1. However, I'm uncertain if these events are being duplicated. Is there an alternative search method I can use to verify whether these events are being double-ingested?
Thanks..
Hi @AL3Z,
if you have results to your search, it should be sure that you have duplicated events.
You can analyze your data to undertand where these duplicates come from and if there's the possibility of duplication.
Ciao.
Giuseppe