Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Avoid indexing same file multiple times batch input

$
0
0
I have batch input [batch://C:\abc\*.zip] move_policy = sinkhole index = xyz host_segment = 2 crcSalt = sourcetype = pqr disabled = false for testing I added one zip file in monitored folder after consumed by splunk I again added same file in monitored folder and I found duplicate events. I was assumed that it will not index same file since I have included `crcSalt=`. What can be done avoid duplication? Note- file monitored is zip- csv file with headers.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>