# Configure log4j2 in Elasticsearch (7x)

**URL:** <https://discuss.elastic.co/t/configure-log4j2-in-elasticsearch-7x/224777>\
**Category:** Elasticsearch\
**Created:** [March 24, 2020, 7:19am UTC](https://discuss.elastic.co/t/configure-log4j2-in-elasticsearch-7x/224777 "2020-03-24T07:19:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [March 24, 2020, 7:19am UTC](https://discuss.elastic.co/t/configure-log4j2-in-elasticsearch-7x/224777/1 "2020-03-24T07:19:35Z")

</div>

Hi everyone,

I have just installed **Elasticsearch 7.5.2** on **Ubuntu 16.04** and I would like to configure **Elasticsearch** in order to retain only two log compressed files in **/var/log/elasticsearch**.

I have modified **log4j2.properties** ( **/etc/elasticsearch** ) according to the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/logging.html).

```auto
######## Server JSON ############################
appender.rolling.type = RollingFile
appender.rolling.name = rolling
appender.rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_server.json
appender.rolling.layout.type = ESJsonLayout
appender.rolling.layout.type_name = server

appender.rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}-%d{yyyy-MM-dd}-%i.json.gz
appender.rolling.policies.type = Policies
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.rolling.policies.time.interval = 1
appender.rolling.policies.time.modulate = true
appender.rolling.policies.size.type = SizeBasedTriggeringPolicy
appender.rolling.policies.size.size = 128MB
appender.rolling.strategy.type = DefaultRolloverStrategy
appender.rolling.strategy.action.type = Delete
appender.rolling.strategy.action.basepath = ${sys:es.logs.base_path}
appender.rolling.strategy.action.condition.type = IfFileName
appender.rolling.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*
appender.rolling_old.strategy.action.condition.nested_condition.type = IfLastModified
appender.rolling_old.strategy.action.condition.nested_condition.age = 2D

```

It is correct? Is there any way to verify it it is working?

Thank in advance,

Regards 🖖

⚠ **Update**

I have modified **log4j2.properties** in order to roll logs after **100MB** ( **appender.rolling.policies.size.size** ) and keep only **10** compressed files ( **appender.rolling.strategy.max** ).

```auto
######## Server JSON ############################
appender.rolling.type = RollingFile
appender.rolling.name = rolling
appender.rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_server.json
appender.rolling.layout.type = ESJsonLayout
appender.rolling.layout.type_name = server

appender.rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}-%d{yyyy-MM-dd}-%i.json.gz
appender.rolling.policies.type = Policies
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.rolling.policies.time.interval = 1
appender.rolling.policies.time.modulate = true
appender.rolling.policies.size.type = SizeBasedTriggeringPolicy
appender.rolling.policies.size.size = 100MB
appender.rolling.strategy.type = DefaultRolloverStrategy
appender.rolling.strategy.max = 10

```

---

<div class="post-metadata">

**Author:** ![bodo.te](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bodo.te/32/54029_2.png) [@bodo.te](https://discuss.elastic.co/u/bodo.te)\
**Post date:** [March 25, 2020, 9:39pm UTC](https://discuss.elastic.co/t/configure-log4j2-in-elasticsearch-7x/224777/2 "2020-03-25T21:39:42Z")

</div>

If you use log4j2 , I would recommend my advise given in this thread: [MDC logs, ELK and filebeat](https://discuss.elastic.co/t/mdc-logs-elk-and-filebeat/222413/7)

---

<div class="post-metadata">

**Author:** ![RdrgPorto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rdrgporto/32/13278_2.png) [@RdrgPorto](https://discuss.elastic.co/u/RdrgPorto)\
**Post date:** [March 26, 2020, 7:02am UTC](https://discuss.elastic.co/t/configure-log4j2-in-elasticsearch-7x/224777/3 "2020-03-26T07:02:25Z")

</div>

Hi @bodo.te ,

Thanks 🙂

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2020, 7:02am UTC](https://discuss.elastic.co/t/configure-log4j2-in-elasticsearch-7x/224777/4 "2020-04-23T07:02:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
