Splunk Search

Issues with Rollup Events

SplunkDash
Motivator

Hello,

I have a Roll Up events. One file created every month and new events added up every day within that file. How would I avoid duplicate ingestion (or avoid same events to be indexed twice) for the same events as SPLUNK is using the same file to read and ingest? Any help will be highly appreciated. Thank you.

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkDash ,

if you don't use crcSalt = <SOURCE> option, Splunk recognizes already indexed events and it doesn't index them twice. even if they come from files with different filenames.

The only situation where the same logs from different files are indexed is using the above option in inputs.conf.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkDash ,

if you don't use crcSalt = <SOURCE> option, Splunk recognizes already indexed events and it doesn't index them twice. even if they come from files with different filenames.

The only situation where the same logs from different files are indexed is using the above option in inputs.conf.

Ciao.

Giuseppe

SplunkDash
Motivator

Hello @gcusello 

I posted a new question here (in following link), would it be possible to have your recommendation when you get a chance, thank you so much.

Re: Field Extraction -Key/ Value Pairs with Specia... - Splunk Community

 

 

Tags (1)
0 Karma

SplunkDash
Motivator

Hello @gcusello,

Thank you so much for your respond, it's answered major part of my question. But, other part of my question, new records/events added everyday within the same file (like added at the end of the same file)), how SPLUNK will ingest/treat those new events/records as those new events will be within the same file?

0 Karma

yeahnah
Motivator

Hi @SplunkDash 

I've read your question a couple of times but I still do not really understand what you are asking.  Please expand on the situation you describe and provide examples.

If it is just that a file is renamed each month in a monitored folder, then this is OK, as Splunk does not track files by only their filename.  It also check sums the first 256 bytes of the head of the file, so if it is renamed then it knows it has already ingested it. 

Anyway, best to describe your concern better so the correct answer can be provided. 

SplunkDash
Motivator

Hello @yeahnah 

Thank you so much for your quick response. My question was, new records/events added everyday within the same file (like at the end of the same file)), how SPLUNK will ingest those new events/records? 

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco &#43; Splunk! We’ve ...