Hi,
I have syslog messages being sent to two different servers. Each server should receive the same events. If the configuration is the same, will I receive 2 events for each syslog entry, or will Splunk make some effort to deduplicate them?
You will get 2 events - both indexers will faithfully index the data that is sent to them.
you can however use the 'dedup' command when searching if you actually have to index the events twice.