Splunk Search

Issues with Rollup Events

SplunkDash
Motivator

Hello,

I have a Roll Up events. One file created every month and new events added up every day within that file. How would I avoid duplicate ingestion (or avoid same events to be indexed twice) for the same events as SPLUNK is using the same file to read and ingest? Any help will be highly appreciated. Thank you.

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkDash ,

if you don't use crcSalt = <SOURCE> option, Splunk recognizes already indexed events and it doesn't index them twice. even if they come from files with different filenames.

The only situation where the same logs from different files are indexed is using the above option in inputs.conf.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkDash ,

if you don't use crcSalt = <SOURCE> option, Splunk recognizes already indexed events and it doesn't index them twice. even if they come from files with different filenames.

The only situation where the same logs from different files are indexed is using the above option in inputs.conf.

Ciao.

Giuseppe

SplunkDash
Motivator

Hello @gcusello 

I posted a new question here (in following link), would it be possible to have your recommendation when you get a chance, thank you so much.

Re: Field Extraction -Key/ Value Pairs with Specia... - Splunk Community

 

 

Tags (1)
0 Karma

SplunkDash
Motivator

Hello @gcusello,

Thank you so much for your respond, it's answered major part of my question. But, other part of my question, new records/events added everyday within the same file (like added at the end of the same file)), how SPLUNK will ingest/treat those new events/records as those new events will be within the same file?

0 Karma

yeahnah
Motivator

Hi @SplunkDash 

I've read your question a couple of times but I still do not really understand what you are asking.  Please expand on the situation you describe and provide examples.

If it is just that a file is renamed each month in a monitored folder, then this is OK, as Splunk does not track files by only their filename.  It also check sums the first 256 bytes of the head of the file, so if it is renamed then it knows it has already ingested it. 

Anyway, best to describe your concern better so the correct answer can be provided. 

SplunkDash
Motivator

Hello @yeahnah 

Thank you so much for your quick response. My question was, new records/events added everyday within the same file (like at the end of the same file)), how SPLUNK will ingest those new events/records? 

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...