I'm very surprised to see that whenever Splunkweb announces a number of events, below, I see exactly the double of events: if Splunk says it has found 3 events, below I see exactly 6 events, three original ones and three duplicates that are perfectly identical, come from the same host...
Could there be a logical reason for this?