# Duplicate logs In Kibana

**URL:** https://discuss.elastic.co/t/duplicate-logs-in-kibana/213562
**Category:** Logstash
**Created:** [January 2, 2020, 11:09am UTC](https://discuss.elastic.co/t/duplicate-logs-in-kibana/213562 "2020-01-02T11:09:33Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Shlok\_Srivastava1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shlok_srivastava1/32/47173_2.png) [@Shlok\_Srivastava1](https://discuss.elastic.co/u/Shlok_Srivastava1)
#### Post date: [January 2, 2020, 11:09am UTC](https://discuss.elastic.co/t/duplicate-logs-in-kibana/213562/1 "2020-01-02T11:09:33Z")

</div>

I am getting Double logs for every api hits in Kibana.

Following is my logstash configuration assuming the issue is related to logstash

```
input {
 beats {
   port => 5044
  ssl => false
  }
}
           
output {
elasticsearch {
    hosts => ["localhost:9200"]
    manage_template => false
    index => "%{[@metadata][type]}-%{+YYYY.MM.dd}"
  	document_type => "log"
 }
}

```

I fixed the above issue using fingerprints and now onwards I am not getting any duplicates. However old logs are the same i.e, they are having duplicates. Is there any way to reset them?

---

<div class="post-metadata">

### Author: ![Rob\_wylde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rob_wylde/32/58231_2.png) [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)
#### Post date: [January 5, 2020, 4:36am UTC](https://discuss.elastic.co/t/duplicate-logs-in-kibana/213562/2 "2020-01-05T04:36:17Z")

</div>

Can we also see the filebeat.yml file?

Also try removing "document\_type" from your output as that option is deprecated. Is there a specific reason you've set manage\_template to false?

Additionally why not just point filebeat directly at elastic if you're not doing any filtering in logstash?

This article may aid in the remove of duplicates. [https://www.elastic.co/blog/how-to-find-and-remove-duplicate-documents-in-elasticsearch](https://www.elastic.co/blog/how-to-find-and-remove-duplicate-documents-in-elasticsearch)

---

<div class="post-metadata">

### Author: ![Shlok\_Srivastava1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shlok_srivastava1/32/47173_2.png) [@Shlok\_Srivastava1](https://discuss.elastic.co/u/Shlok_Srivastava1)
#### Post date: [January 6, 2020, 6:51am UTC](https://discuss.elastic.co/t/duplicate-logs-in-kibana/213562/3 "2020-01-06T06:51:33Z")

</div>

```
###################### Filebeat Configuration Example 
#########################

filebeat.inputs:

- type: log

  enabled: true

  paths:
#- /var/log/*.log
#- /var/log/apache2/*.log
- /home/ubuntu/ProjectName/logs/*
#- c:\programdata\elasticsearch\logs\*

filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml

setup.template.settings:
  index.number_of_shards: 3

output.logstash:
  hosts: ["localhost:5044"]

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

```

Inside the location, I have multiple files resembling logs of each past day (eg log-31-12-2019) and one log of the current day. I have checked manually the duplication is not present here.

There isnt any specific reason for putting manage\_template as false. I kinda copy pasted it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 3, 2020, 7:00am UTC](https://discuss.elastic.co/t/duplicate-logs-in-kibana/213562/4 "2020-02-03T07:00:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
