# Configure log4j to hide WARN in elasticsearch

**URL:** <https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086>\
**Category:** Elasticsearch\
**Created:** [May 28, 2019, 11:47am UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086 "2019-05-28T11:47:31Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [May 28, 2019, 11:47am UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/1 "2019-05-28T11:47:31Z")

</div>

Hi everyone!  
I'm using elasticsearch v 7.1 and v 6.2 and I'm trying to configure elastic log via log4j.properties file to show only info and errors, and hide the warnings.  
How do I do that?  
I tried to read the apchee page but I didn't see any direct refrence to this issue or to configuring via file.  
I looked at the elastic page - [Logging | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/logging.html)  
and didn't find any answers there either.

I only changed the line:

```
logger.action.name = org.elasticsearch.action
logger.action.level = debug

```

to:

> logger.action.name = org.elasticsearch.action  
> logger.action.level = error

But it didn't work.  
What to I need to change or add in order to make sure that elastic report only on the ERROR and INFO levels, and not WARN?

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [May 31, 2019, 9:53pm UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/2 "2019-05-31T21:53:42Z")

</div>

I don't think it is possible. Logging levels are linear, and to set the logging level to info, it will always include warn and error.

Note that the logger you changed is just a child logger for actions, not for the entire log.

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [May 31, 2019, 9:55pm UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/3 "2019-05-31T21:55:51Z")

</div>

Actually, it _could_ be done, but you would need to write your own log4j appender to customize not propagate warn messages.

However, this is really not recommended. Why do you want to omit warning messages? They are important, and ignoring them can lead to problems later, like when upgrading.

---

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [June 2, 2019, 5:43am UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/4 "2019-06-02T05:43:15Z")

</div>

Because in my application sometimes I send a request to delete a non existing index, and the error stack from this action fills up my logs.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 2, 2019, 6:28am UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/5 "2019-06-02T06:28:50Z")

</div>

Why not change your code to check if the index exists before deleting it?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 2, 2019, 6:34am UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/6 "2019-06-02T06:34:13Z")

</div>

If you are deleting with a wildcard or multiple indices at the same time, you can use the following options: [https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-index.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-index.html)

It might help.

If it's a specific index you want to delete, just do what @Christian_Dahlqvist proposed.

---

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [June 2, 2019, 8:48am UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/7 "2019-06-02T08:48:08Z")

</div>

I use the wildcard, the error I get is a wildcard expetion, index does not exist.

> org.elasticsearch.cluster.metadata.IndexNameExpressionResolver$WildcardExpressionResolver.indexNotFoundException(IndexNameExpressionResolver.java:747) ~[elasticsearch-7.1.0.jar:7.1.0]

Anyway, I understand that there is no way to avoid this warning without changing the way my app sends requests...

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 2, 2019, 9:10am UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/8 "2019-06-02T09:10:08Z")

</div>

Can you share exactly what you are doing, like the code?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2019, 9:10am UTC](https://discuss.elastic.co/t/configure-log4j-to-hide-warn-in-elasticsearch/183086/9 "2019-06-30T09:10:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
