I feel like at this point this is another reason to look at upgrading to 5.x. I'm fairly sure you can work out all kinds of logging stuff in 2.x but 5.x runs on log4j2 and uses log4j2's standard properties file so all the instructions on the internet about configuring log4j2 should be accurate for elasticsearch.
1 Like