I have a very simple elkstack POC environment using Filebeat > logstash > elasticsearch > kibana
All have been updated to 5.2 previously used 5.0
None of the elk stack components are clustered
If I remove filebeat and use a file as input into logstash, the number of events created is as expected.
However, when I use filebeat as an input (and the same file being ingested), I get over 10% more events.
Having trawled through the output, these are duplicate events created by filebeat that do not exist as duplicated in the input file.
Is this an issue with filebeat? are there any suggested work arounds for this?