# Duplicate Logs Issue Due to next\_start\_date Configuration in Google Workspace Admin Module

**URL:** https://discuss.elastic.co/t/duplicate-logs-issue-due-to-next-start-date-configuration-in-google-workspace-admin-module/372082
**Category:** Beats
**Tags:** filebeat
**Created:** [December 17, 2024, 3:54pm UTC](https://discuss.elastic.co/t/duplicate-logs-issue-due-to-next-start-date-configuration-in-google-workspace-admin-module/372082 "2024-12-17T15:54:49Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Ninas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ninas/32/140079_2.png) [@Ninas](https://discuss.elastic.co/u/Ninas)
#### Post date: [December 17, 2024, 3:54pm UTC](https://discuss.elastic.co/t/duplicate-logs-issue-due-to-next-start-date-configuration-in-google-workspace-admin-module/372082/1 "2024-12-17T15:54:50Z")

</div>

While using the [Google Workspace Admin module](https://github.com/elastic/beats/blob/main/x-pack/filebeat/module/google_workspace/admin/config/config.yml) for Filebeat, I've encountered an issue where duplicate logs are being received.

The problem seems to originate from the `url.params.startTime` configuration, particularly with the following logic:

```auto
value: >-
        [[- if eq .cursor.pagination_finished "true" -]]
          [[- .cursor.next_start_date -]]
        [[- else -]]
          [[- .cursor.last_response_date -]]
        [[- end -]]
      default: '[[formatDate (now (parseDuration "-{{.initial_interval}}"))]]'

```

Here, `next_start_date` is being set to `[[.first_event.id.time]]` (the event time). However, this causes the module to set the `startTime` parameter to the time of the event, resulting in the same event being pulled repeatedly.

Since `startTime` sets the beginning of the range for the logs, this behavior causes multiple logs to be received for the same event, leading to duplication.

**Steps to Reproduce:**

1. Configure the Google Workspace Admin module as per the [documentation](https://github.com/elastic/beats/tree/main/x-pack/filebeat/module/google_workspace/admin).
2. Enable the module and start Filebeat.
3. Observe the logs being ingested.

**Environment** :  
Filebeat version: 8.16.1  
Module: Google Workspace Admin

Has anyone found a workaround or solution to prevent this behavior?

Thank you in advance!
