Hi, I have installed a splunk server in one system and one universal forwarder in another system. I am monitoring a circular log(when the log reaches a particular size the log entries from the bottom gets deleted and new entries comes at the top of the file) with universal forwarder.
The problem i am facing is that when any new entry comes at the top of the file the splunk parses the whole log file and creates duplicate events in the index.
Is there any way so that i can tell splunk to ignore a event if it is already present in the index or to overwrite a event if it is already in the index and only store the new entry in the index.
I am working on it for last 2 days but no solution till now, any help is appreciated.
Thanx,
SD
... View more