Splunk Cloud Platform

Duplicate events in Splunk from Aws cloud watch

Poojary
New Member

I am getting the Duplicate events in Splunk from Aws cloud watch and I am sending data from only one source to the Splunk .
How do I resolve it.

Labels (1)
0 Karma

nyc_jason
Splunk Employee
Splunk Employee

depending on your method of collection, please see here: https://docs.splunk.com/Documentation/AddOns/released/AWS/ConfigureInputs

Note this portion in case you are under this scenerio:

Note: It is a best practice to collect VPC flow logs and CloudWatch logs through Kinesis streams. However, the AWS Kinesis input has the following limitations:

Multiple inputs collecting data from a single stream cause duplicate events in the Splunk platform.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...