Right now I am just working on a proof of concept locally and am not using a Logstash Forwarder. I am manually running logstash from the DOS Prompt to load data from an Apache Access Log into elasticsearch
Assume that I already have data indexed in elasticsearch. I do not want duplicate documents in elasticsearch. If I use logstash to an Apache Log File, if logstash/elasticsearch determines that the data from the log file already exists in elasticsearch, will the already indexed data in elasticsearch get duplicated or will the already indexed data be deleted and then re-added to elasticsearch (no duplication)?