I have a new and pretty basic installation of Graylog up and running, and I am getting some duplicate logs. I’m pulling in logs via rsyslog ex.
Adding Graylog log files
Send Graylog Web Server logs
Send logs to Graylog
Currently there is only one stream (the default All Messages stream). There is only one node. There is only one index (which does currently have 2 indices, of which only one is marked as active write index).
I have verified the raw logs do not contain duplicates, and I have verified that the above rsyslog config is the only service sending logs.
Any advice on where to continue troubleshooting would be appreciated.