My app notifies Splunk with the call to HEC on data changes. As data actually stored as series of events, it is quite straightforward to use Splunk for analysis. But, due to some internal reasons, it is possible that same events will be delivered to HEC twice. And it is crucial to have only one event stored in Splunk in this case.
Most obvious way to achieve this is to have some unique id posted with event and having Splunk ignore the event if it has id matching any of previously indexed events. But, I failed to find anything like this in the documentation.
... View more