Deployment Architecture

Splunk Enterprise Security Search Head returning dual events

bsuresh1
Path Finder

We are using Splunk 6.5 environment with 5 (4+1) Search Heads where the latest SH is dedicated for Enterprise Security app and this was installed few weeks back. Only in this ES Search Head, we are getting dual events. If we get 50 events in other 4 Search Heads, we are getting 100 events in ES search head.

Could you please let me know how to fix this?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

ES is a very complex App to setup and configure. Without knowing how your core Splunk deployment is built out, it is very difficult to assist on this. If this is a new deployment, I would find out who deployed it and talk to them. Typically Splunk requires Pro Serv for ES deployments, and partners follow the same model. So if this is a new deployment, talking to the team that deployed would be your quickest solution.

There could potentially be a lot of issues here.

Can you describe your deployment? How many indexers, cluster configuration, search head configuration etc?

Is this a new deployment? Or did you inherit it from another admin?

0 Karma

bsuresh1
Path Finder

Splunk professionals have deployed ES app and all the configurations were made by them.

In Indexer clustering, we have 8 indexers and 3 SH's. As per the below link, I understand that we need to configure indexer clustering for the Search Head to have no duplicate events. I am going to do this and check.

Please let me know if any other suggestion.

https://answers.splunk.com/answers/481498/how-to-prevent-duplicate-events-from-occurring-whe.html

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...