I have about 50 forwarders in my environment. Somewhere I have screwed up, and included the same set of host data twice, but one with a typo. I went to the inputs.conf and looked at the stanza, and I only have the correctly spelled host. So somewhere I have messed something up.
How can I tell where a particular host's data is coming from? (preferrably the IP address)
Thanks, Sean
OK, I found it by looking through the splunkd.log file.
I looked for the host in question, and looked for the connections around the containing entry. That led me to the inputs.conf file that had the mistake.
Hope this helps someone else in the distant future.