# Duplicate logs in dashboard/search screen

**URL:** <https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891>\
**Category:** Graylog Central (peer support)\
**Created:** [July 20, 2022, 10:37pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891 "2022-07-20T22:37:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![brijesh.kalavadia](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@brijesh.kalavadia](https://community.graylog.org/u/brijesh.kalavadia)\
**Post date:** [July 20, 2022, 10:37pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891/1 "2022-07-20T22:37:08Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.  
**Don’t forget to select tags to help index your topic!**

**1. Describe your incident:**  
Getting Duplicate logs… we have recently set up Graylog 4.3 multinode environment having one master, master-data and data node. we are seeing duplicate logs in dashboard. we have set up stream for GELF and SYSLOG with having separate index sets and have also selected “Remove matches from ‘All messages’ stream” in stream set up… how would I stop having duplicate logs ?

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 20, 2022, 10:44pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891/2 "2022-07-20T22:44:09Z")

</div>

Hello && welcome @brijesh.kalavadia

This depends on how you setup this environment.  
Normally Dup’s are cause by the log shipper. You have multiple streams with multiple index sets?

That is the only reason why Graylog itself would duplicate messages. When a message is in multiple streams that have different index sets as target.

---

<div class="post-metadata">

**Author:** ![brijesh.kalavadia](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@brijesh.kalavadia](https://community.graylog.org/u/brijesh.kalavadia)\
**Post date:** [July 20, 2022, 10:47pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891/3 "2022-07-20T22:47:57Z")

</div>

Thanks for prompt reply… yes I have GELF and SYSLOG with having separate index sets… but shouldn’t “Remove matches from ‘All messages’ stream” settings does removes duplicates ???  
Or is there a way I can stop having duplicates ?

It will be good to have some workaround in place because having duplicate logs on screen some times annoying users while they are running any search query and looking for some logs…

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 20, 2022, 11:24pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891/4 "2022-07-20T23:24:09Z")

</div>

Hello,

From what information is shown, I’m not sure if its a Setting/Configuration issue. What I have experienced with Dup’s message was either misconfiguration with Streams/Indices, Log shippers.  
Pipelines for work-around might be you best bet, but that just a patch, its not fixing this issue.

Maybe check this out [here](https://community.graylog.org/search?q=Messages%20duplication)  
Hope that helps

---

<div class="post-metadata">

**Author:** ![brijesh.kalavadia](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@brijesh.kalavadia](https://community.graylog.org/u/brijesh.kalavadia)\
**Post date:** [July 21, 2022, 2:36pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891/5 "2022-07-21T14:36:58Z")

</div>

I went through the link you provided as well before and in each discussion I found that if you have set up stream store data for separate index set then you will see duplicate data each for stream/index… (Nothing helpful solutions) so I guess I should stop using stream and its settings “Remove matches from ‘All messages’ stream” because that is not working as it suppose to…

My settings are

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/88ffa5f31a73e4bee7a0d70e0c122a844a1d5de6.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/0d1f8880614ea24deafefcfc3a708e5a9b0005ee.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/86f408b1e8eac1643225ca09b2b9cfb2c232b858.png)

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [July 21, 2022, 9:43pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891/6 "2022-07-21T21:43:43Z")

</div>

Hello,

Here is an Idea, Instead of using **gl2\_source\_input** to route message from a INPUT to a INDEX try using something like this.

BTW thanks for the screen shots I was able to see what’s going on. 👍

**Example** :

I have stream that uses a different index.

Stream **Linux Servers**

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/0/057ddd7b98153246cd6f8f9c1a2eab56f414c25a.png)

**Linux Server Stream Rules** configuration BUT I don’t use gl2-souce\_input, I use TYPE “match input” as shown in the red boxes.

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/e8e11e047c37b2f581cf39ee67d4027bfa868ae3.png)

You can tell the difference from the Result Section.

If that what you trying to accomplish.

---

<div class="post-metadata">

**Author:** ![brijesh.kalavadia](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@brijesh.kalavadia](https://community.graylog.org/u/brijesh.kalavadia)\
**Post date:** [July 21, 2022, 10:45pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891/7 "2022-07-21T22:45:48Z")

</div>

Yup… That works thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 4, 2022, 10:46pm UTC](https://community.graylog.org/t/duplicate-logs-in-dashboard-search-screen/24891/8 "2022-08-04T22:46:00Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
