Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Huge duplicate and unwanted data into Index

$
0
0
Dear All, We are getting huge duplicate data and unwanted data into splunk and while we are querying the performance is getting effected. Below is the senario: We are using HF to push the data into Splunk Cloud. **this is an example of duplicate data.** source type A: 1, AA Source Type A: 1, AA **This is an example of unwanted data:** source type A: 1, AA Source Type A: 1, AB Here second one got updated by AB and we wont be needing first one(AA) any more any more. Because of this splunk scans 20,00,00,000 events and out of that we get 1,50,00,000 which are useful. Can someone suggest better way to maintain data in index. Regards, Santosh

Viewing all articles
Browse latest Browse all 47296

Trending Articles