The Elastic Agent collects Filebeat logs. Within 'Fleet' I have the system-1 default. This module collects the logs form usual logfiles like /var/log/syslog* etc.
But also the logs from /var/lib/elastic-agent/logs/default/filebeat-json.log. Now I have all events duplicated. The latter ones are not parsed, the logs from /var/log are correctly parsed.
Why are there logs also collected?