Introduction
Problem
Duplicate log entries are observed being forwarded to Splunk after configuring or updating the HCP Terraform for Splunk application.
Cause
- Upon removal/reinstallation, HCP Terraform for Splunk's configured Data Inputs are not removed from the Splunk App. This results in duplicate log entries.
Solutions:
- Log in to the Splunk App.
- Navigate to Settings | Data Inputs
- Find the HCP Terraform For Splunk entry and expand that item to view the inputs
- Delete any extra inputs, there should only be 1 input listed