Our elasticsearch _audit.json files get rolled over daily to -audit-YYYY-MM-DD.json files and appear to be kept for 8 days. For some test nodes, I'd like to reduce the number of days these are kept for disk space usage. I can't find any place in the audit options or settings that controls the retention, is there a retention days option?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.