I have three indices which are sent across from Logstash to Elasticsearch. The logs are of the same format. The difference being they come from different servers and are received at different ports on logstash. The grok pattern for them is exactly the same.
The issue I face now is that every field in each of these three indices are tripling itself. When I remove one of the config files from logstash, the repetition becomes twice. If I add another file i.e four logstash configs , it quadruples. Really odd behaviour.
The "message" field in elasticsearch is normal but its only the fields that are multiplying. Any ideas why such odd behaviour?