|
Hello, I am trying to get events of a windows 2003 server (security logs) using splunk+WMI for windows installed on a XP host. If I restart splunk services all events are being duplicated on the indexer. Is it normal or it should not happen? Thanks in advance and kind regards. Luca. |

You should not be getting duplicate events. WMI should checkpoint what it already got and only request what it doesn't. Can you paste your configuration?