Thanks team.
I read about the deduplication issue.
Duplicate events are overwritten.
If you have ILM policy where you can write to index for 2 days and if logstash will try to write that index ( duplciate events are updated not dropped)
we need to find a way to drop the event if it is overwriting or index based on logstash timestamp no issue will be seen, if it is from timestamp generated from the event metadata then issue starts.