# Duplicate Message sent?

**URL:** <https://discuss.elastic.co/t/duplicate-message-sent/25494>\
**Category:** Logstash\
**Created:** [July 14, 2015, 2:06am UTC](https://discuss.elastic.co/t/duplicate-message-sent/25494 "2015-07-14T02:06:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [July 14, 2015, 2:06am UTC](https://discuss.elastic.co/t/duplicate-message-sent/25494/1 "2015-07-14T02:06:52Z")

</div>

Hi All,

there are 5 hosts (logstash-forwarder \> redis \> logstash-center \> elasticsearch \< Kibana), when I push an message to logstash-forwarder, redis always receives 2 messages, I try to delete the keys of list of redis, but it seems cannot work fine, how to solve the problem, following are my details setting

**logstash-forwarder CONF**  
input {  
file {  
type =\> "type\_count"  
path =\> ["/data/logs/count/stdout.log", "/data/logs/count/stderr.log"]  
exclude =\> ["\*.gz", "access.log"]  
}  
}

output {  
stdout { codec =\> rubydebug }  
redis {  
host =\> "redis"  
port =\> 6379  
data\_type =\> "list"  
key =\> "key\_count\_test"  
}  
}

[root@logstashagent ~]# echo "4999M 9 910 140.92.25.201" \>\> /data/logs/count/stdout.log

**Redis**  
[root@redis ~]# redis-cli  
127.0.0.1:6379\> KEYS \*  
(empty list or set)

[root@redis ~]# redis-cli monitor  
1436839399.032077 [0 140.92.25.88:37476] "blpop" "key\_count\_test" "0" "1"  
1436839399.312106 [0 140.92.25.201:45951] "rpush" "key\_count" "{"message":"4999M 9 910 140.92.25.201","@version":"1","@timestamp":"2015-07-14T02:02:28.251Z","host":["logstashagent","140.92.25.201"],"path":"/data/logs/count/stdout.log","type":"type\_count","memory":"4999M","used":"9","avaliable":"910"}"  
1436839399.315235 [0 140.92.25.88:37463] "blpop" "key\_count" "0" "1"  
1436839399.912829 [0 140.92.25.201:45958] "rpush" "key\_count\_test" "{"message":"4999M 9 910 140.92.25.201","@version":"1","@timestamp":"2015-07-14T02:02:28.857Z","host":"logstashagent","path":"/data/logs/count/stdout.log","type":"type\_count"}"

**logstash-center CONF**  
input {  
redis {  
host =\> "redis"  
port =\> 6379  
type =\> "redis-input"  
data\_type =\> "list"  
key =\> "key\_count\_test"  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
host =\> "elasticsearch"  
codec =\> "json"  
protocol =\> "http"  
}  
}

**Kibana message**

July 14th 2015, 10:02:28.857 message:4999M 9 910 140.92.25.201 @version:1 @timestamp:July 14th 2015, 10:02:28.857 host:logstashagent path:/data/logs/count/stdout.log type:type\_count \_id:AU6KTUQ9neUCreKPrDO- \_type:type\_count \_index:logstash-2015.07.14  
July 14th 2015, 10:02:28.251 message:4999M 9 910 140.92.25.201 @version:1 @timestamp:July 14th 2015, 10:02:28.251 host:logstashagent, 140.92.25.201 path:/data/logs/count/stdout.log type:type\_count memory:4999M used:9 avaliable:910 \_id:AU6KTUHmneUCreKPrDO9 \_type:type\_count \_index:logstash-2015.07.14

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2015, 5:57am UTC](https://discuss.elastic.co/t/duplicate-message-sent/25494/2 "2015-07-14T05:57:16Z")

</div>

Check what files you have in /etc/logstash/conf.d. I suspect you have an extra configuration file with a redis output so that each message is sent to Redis twice.

Note: logstash-forwarder is the name of a program separate from Logstash. The configuration snippet you've shown is for Logstash. To avoid confusion, don't say logstash-forwarder when you mean Logstash.

---

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [July 14, 2015, 9:47am UTC](https://discuss.elastic.co/t/duplicate-message-sent/25494/3 "2015-07-14T09:47:22Z")

</div>

Hi Magnus Back,

Thanks for replying,

**I checked my files of /etc/logstash/conf.d (Logstash) as following**  
[root@logstashagent conf.d]# pwd  
/etc/logstash/conf.d  
[root@logstashagent conf.d]# ll  
total 4  
-rw-r--r--. 1 root root 430 Jul 14 11:17 logstashagent.conf

As my conf file, the key ' **key\_count**' is not exist in output/redis/key anymore, but it always appears in Redis monitor, like  
1436867048.833035 [0 140.92.25.88:37479] "blpop" " **key\_count\_test**" "0" "1"  
1436867049.133807 [0 140.92.25.88:37464] "blpop" " **key\_count**" "0" "1"  
1436867049.434578 [0 140.92.25.88:37463] "blpop" " **key\_count**" "0" "1"  
1436867049.835537 [0 140.92.25.88:37479] "blpop" "key\_count\_test" "0" "1"  
1436867050.136416 [0 140.92.25.88:37464] "blpop" "key\_count" "0" "1"  
1436867050.437172 [0 140.92.25.88:37463] "blpop" "key\_count" "0" "1"

I tried to restart all services but the problem still exist

---

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [July 15, 2015, 9:50am UTC](https://discuss.elastic.co/t/duplicate-message-sent/25494/4 "2015-07-15T09:50:03Z")

</div>

Hi Magnus,

finally I delete xxx.conf.swp file, and it works normally

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:34am UTC](https://discuss.elastic.co/t/duplicate-message-sent/25494/5 "2017-07-06T05:34:40Z")

</div>


