Can you show what your agent group definition looks like for this host? What version of vRLI and agent are you using?
Using the lastest version of RLI on every agent, 22.214.171.12487550
My agent groups are setup like;
- Windows servers: (based on OS)
-- Getting Windows event logs
- Webservers (based on name)
-- Getting IIS Logs.
I've checked if I have set up multiple times the event logs like Windows servers which are Webservers also, but don't do that...
On this particular host:
because its a windows server also;
As you see, no duplicates in receiving Event logs
I also checked other Windows VM's if they have the same issue and they also have the same issue.
Do your non-Windows VMs not have this problem? Look at the agent logs on one of those Windows servers. Anything there indicate duplicate events? Wondering if duplicates are actually being sent or if this is a duplicate display issue at the vRLI server side.
Also an Ubuntu VM has duplicate entry's.
I checked on that Ubuntu VM and I only see 1 entry in the that specific log
Looking at the LOG of LiAgent and I see on the Ubuntu VM:
2 server-sections.... hmm... thats interesting because I know why that is....
In the Logagent-config
I though I should see something like SERVER2, because I do have that in my Windows and that is because I've set that up in my agent group;I did that because I want to use CAFI-protocol, but I don't have yet valid SSL certificates.By using this SERVER2 setting, I have the optionI also tried to rename SERVER2 to SERVER but that won't work because server already exists.So this all kind be the cause of my duplicate entry's, but can you tel me how I can go arround the issue with my invalid SSL certificates ?The loginsight-server itself has a valid SSL certificate but my VM's not.
So then that's likely the cause. If you don't have the SSL cert trusted on the node sending logs, then no point in using SSL. So you need just a single host defined because otherwise it's duplicating those messages.