When rotation happens we see that the last entry durring rotation gets cut in half. So some of the bytes of the line are in the old file and the rest in the new file.
This single line gets indexed as 2 separate events in ES.
TBH I don't know. I would recommend to check the rotated log files and see if the messages are truncated.
TBH I would be surprised if logrotate with a default config cuts log lines in half as if this is the case I would expect quite a few more reports of this problem.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.