I have the following setup (single node):
Logstash 2.1.0 + Elasticsearch 2.1.0 + Kibana4 and logstash receiving logs from different sources (nxlog, syslog forward and etc..). I am seeing exactly 9 duplicate events for the each logs received:
Jan 30 11:13:12 rhel sshd: Failed password for root from 192.168.1.1 port 43242 ssh2
The above log turns into 9 entries in elasticsearch. But I tried to send the output to "file" and there are no duplicates. I am having only issue with elasticsearch output. The following is the output config:
hosts => "localhost"
Please help me to solve this issue.