Hello,
Something similar happened to me, we had an TA Addon arista and the app Arista operating in the Search Head, we found that there was a duplicate word "speed" in a CSV but there was no reference to what lookup it was.
Error
"09-19-2019 22:05:14.045 -0500 WARN SearchResultsCSVSerializer - Corrupt csv header, 2 columns with the same name 'speed' (col #3 and #0, #3 will be ignored)"
Solution - Find the speed word in the csv files of the splunk apps directory.
grep -Rw '/opt/splunk/etc/apps/' -e 'speed' --include=*.csv
Output
/opt/splunk/etc/apps/TA-arista/lookups/interface-speed.csv:speed,"speed_desc",Speed
/opt/splunk/etc/apps/aristanetworks/lookups/interface-speed.csv:speed,"speed_desc",speed
Then delete the app or duplicate csv (In my case delete the app contain csv duplicate)
/opt/splunk/bin/splunk stop
rm -rf /opt/splunk/etc/apps/aristanetworks
/opt/splunk/bin/splunk start
Validate log level (error, warn)
tail -f tail -f /opt/splunk/var/log/splunk/splunkd.log
OR Query SPL
index="_internal"
| search log_level!="info"
| stats values(component) count by log_level
🙂
... View more