We have a dozen or so servers we pull access logs off of with logstash running on each of those and they're sent to our ES cluster. I've now configured a 1 hour Rollup in our ES cluster. Over the years we've run into a few occurrences where Logstash was down for a day or two before we caught the problem at which point we started up logstash and all the old records were sent to ES.
But what happens with rollups in this scenario. If the rollup job is running every hour will it detect that older data was added to ES? Or will it simply be ignored?