# Conf configuration

**URL:** <https://discuss.elastic.co/t/conf-configuration/190066>\
**Category:** Logstash\
**Created:** [July 11, 2019, 4:11pm UTC](https://discuss.elastic.co/t/conf-configuration/190066 "2019-07-11T16:11:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Krishna\_Pagar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishna_pagar/32/49908_2.png) [@Krishna\_Pagar](https://discuss.elastic.co/u/Krishna_Pagar)\
**Post date:** [July 11, 2019, 4:11pm UTC](https://discuss.elastic.co/t/conf-configuration/190066/1 "2019-07-11T16:11:45Z")

</div>

Hi,

I have created conf file with below details, but whenever I am searching in Kibana with type - auth\_inbound\_web I can see all logs with only 7 days. I need that for 30 days.

# There are 2 Index namely - logstash-test-prd0-30-auth-%{+YYYY.MM.dd} ----- which shows logs for 30 days logstash-test-prd0-7-auth-%{+YYYY.MM.dd} ----- which shows logs for 7 days

[root@123]# cat output.conf  
output {  
if "test\_inbound\_web" in [type]  
{  
elasticsearch  
{  
hosts =\> ["[testchesclientnode.anr53p.co.uk:9200](http://testchesclientnode.anr53p.co.uk:9200)"]  
manage\_template =\> false  
index =\> "logstash-test-prd0-30-auth-%{+YYYY.MM.dd}"  
}  
}  
else if "offduty" in [type] {  
elasticsearch {  
hosts =\> ["[testchesclientnode.anr53p.co.uk:9200](http://testchesclientnode.anr53p.co.uk:9200)"]  
manage\_template =\> false  
index =\> "logstash-test-prd0-7-test-%{+YYYY.MM.dd}"  
}  
}  
}

=============================================  
[root@123]# cat input.conf  
input {  
file {  
path =\> "/logs/apache/test\_secure\_inbound.log"  
type =\> "test\_inbound\_web"  
tags =\> ["test", "web", "apache", "access", "test", "test\_secure\_inbound", "apache\_combined\_timings", "prd0"]  
}  
file {  
path =\> "/logs/apache/offduty\_test\_secure\_inbound.log"  
type =\> "test\_inbound\_web"  
tags =\> ["test", "web", "apache", "access", "offduty","test", "test\_secure\_inbound", "apache\_combined\_timings", "prd0"]  
}  
}  
}  
filter {  
if "apache\_combined\_timings" in [tags] {  
grok {  
match =\> ["message", "%{COMBINEDAPACHELOG:log} %{NUMBER:response\_time} "%{DATA:api\_transaction\_id}" "%{DATA:apigw\_authenticated\_client}""]  
}  
}  
}

Thanks,

---

<div class="post-metadata">

**Author:** ![Krishna\_Pagar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishna_pagar/32/49908_2.png) [@Krishna\_Pagar](https://discuss.elastic.co/u/Krishna_Pagar)\
**Post date:** [July 12, 2019, 3:06pm UTC](https://discuss.elastic.co/t/conf-configuration/190066/2 "2019-07-12T15:06:44Z")

</div>

can someone help me in this ?

Thanks

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 12, 2019, 4:43pm UTC](https://discuss.elastic.co/t/conf-configuration/190066/3 "2019-07-12T16:43:13Z")

</div>

Read [this](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and specifically the "Also be patient" part.

It's fine to answer on your own thread after 2 or 3 days (not including weekends) if you don't have an answer.

I moved your question to #logstash.

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 12, 2019, 5:09pm UTC](https://discuss.elastic.co/t/conf-configuration/190066/4 "2019-07-12T17:09:56Z")

</div>

I would agree with everything David said, but the logstash configuration does not matter. It does not affect how long data is retained in elasticsearch. Are you using ILM? Are you using curator?

---

<div class="post-metadata">

**Author:** ![Krishna\_Pagar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krishna_pagar/32/49908_2.png) [@Krishna\_Pagar](https://discuss.elastic.co/u/Krishna_Pagar)\
**Post date:** [July 20, 2019, 11:30pm UTC](https://discuss.elastic.co/t/conf-configuration/190066/5 "2019-07-20T23:30:51Z")

</div>

It's logstash agent which push logs to Kibana, but when I check in Kibana it showing only 7 days logs which I need for 30 days... can you please help me and confirm whether output / input file is correct one ?

Thanks,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 21, 2019, 12:05pm UTC](https://discuss.elastic.co/t/conf-configuration/190066/6 "2019-07-21T12:05:44Z")

</div>

What are you using to delete old logs from elasticsearch?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2019, 12:05pm UTC](https://discuss.elastic.co/t/conf-configuration/190066/7 "2019-08-18T12:05:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
