I am getting the Duplicate events in Splunk from Aws cloud watch and I am sending data from only one source to the Splunk .
How do I resolve it.
depending on your method of collection, please see here: https://docs.splunk.com/Documentation/AddOns/released/AWS/ConfigureInputs
Note this portion in case you are under this scenerio:
Note: It is a best practice to collect VPC flow logs and CloudWatch logs through Kinesis streams. However, the AWS Kinesis input has the following limitations:
Multiple inputs collecting data from a single stream cause duplicate events in the Splunk platform.