Yesterday i cam across something i can't understand.
Let's say i stopped my logstash at 10 AM and put it back on at 12, usually logs are coming and re-ordered as normal ( i can't figure how since @timestamp field should be ingest time ). As normal i mean it's near their creation time and everything is put back in the timeline.
Yesterday my pattern had a conflict or missing field and when i started my logstash every logs were spiking and @timestamp at the time i started my logstash thus creating a false timeline.
I tried to reproduce it but it looks like i am missing some pieces of informations.
My logs are shipped through filebeat to logstash then elastic.