Duplicate logs are found when using Syslog-ng Windows Event Collector (WEC).
In certain cases (for example when events are sent through multiple Windows machines), the EventRecordID (which is currently used in Syslog-ng Window Event Collector (WEC) for per-event bookmark handling) is not the same as internal RecordID (which is used by the official event collector to keep track of events).
This can result in message duplication or loss.
This issue has been resolved in Syslog-ng PE version 7.0.23.
Please upgrade to this version, or a more recent version, to ensure this issue has been resolved.