I configured logstash to retreive all data of one index from elasticsearch using elasticsearch plugin -> http://logstash.net/docs/1.2.2/inputs/elasticsearch
The output is to a file. But, some strange behaviour ocurred: Instead of logstash write all documents collected from that index to the output file, it wrote to the index itself, duplicating all of the documents (4 millions). Now, I dont know how can I search for the duplicate entries because it copied all of the fields exactly as they are, changing only the _id field.
My logstash instance is running loading only one config file:
What I did wrong?