Thanks for getting back and No, that does not justify.
I am talking about the diagram where each Logstash shipping instance (3 shipping instance processing all 4 source types and especially from same sources) is processing all types of message sources - UDP, File, RSS and Twitter input plugins. Can you explain what is the intended idea behind this stack implementation and how to avoid duplicate message processing in such an architecture setup.
As per my understanding, for providing HA, the diagram shows multiple shipping instances reading from same source. So all the messages logged from the same source will be read by all shipping instances and sent to its individual messaging queue. So from there hope you can imagine how the duplicate messages flow through the system pipeline.
Please clarify if my understanding is incorrect.