Duplicate data.
I am noticing that we are getting 4 identical lines occurring when i issue a search from a search head.
This is using an indexer cluster (4 nodes, 2 at each Data Center) and forwarders that are configured to use native loadbalancing, along these lines:
http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Aboutclusters
Would the expectation with such a cluster just be one line per logfile entry? Have we done something wrong? Is the duplication more likely to be the index cluster or the forwarders - is there a way to determine ?
by any chance were you using useAck?
So what was the final outcome? Did you end up figuring out the root cause?