Can you please specify the way this log is generated? Looking at the log snippet provided, this looks to be an issue with the way log is updated, since splunk indexes the log file and every new entry in the log should only get indexed. But, in this case, looking at the log snippet, looks like each updated entry is updating/refreshing the whole log file itself, making splunk to consider this as a new file to be indexed again since the crc value has changed:
02-19-2019 15:30:02.144 +0100 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/net/dell479srv/dell479srv2/apps/TheOne-RSAT/qcstTools/qcstOutFiles/qcst_out_toolsMonitoring_CheckToolLifeCycle.txt'.
... View more