# Delete old logs files

**URL:** <https://discuss.elastic.co/t/delete-old-logs-files/318317>\
**Category:** Elasticsearch\
**Created:** [November 7, 2022, 10:54am UTC](https://discuss.elastic.co/t/delete-old-logs-files/318317 "2022-11-07T10:54:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ludovic9](https://avatars.discourse-cdn.com/v4/letter/l/977dab/32.png) [@Ludovic9](https://discuss.elastic.co/u/Ludovic9)\
**Post date:** [November 7, 2022, 10:54am UTC](https://discuss.elastic.co/t/delete-old-logs-files/318317/1 "2022-11-07T10:54:30Z")

</div>

Hi  
I'm using an old version of elasticsearch (6.4.1).  
In /var/log/elasticsearch I have a lot of logs file since 2018 with log.gz extension.

It seems using logrotate is not a good option, but instead, using the parameters in log4j2.properties.

However, in this file, the configuration seems good :

```auto
appender.rolling.type = RollingFile
appender.rolling.name = rolling
appender.rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}.log
appender.rolling.layout.type = PatternLayout
appender.rolling.layout.pattern = [%d{ISO8601}][%-5p][%-25c{1.}] %marker%.-10000m%n
appender.rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}-%d{yyyy-MM-dd}-%i.log.gz
appender.rolling.policies.type = Policies
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.rolling.policies.time.interval = 1
appender.rolling.policies.time.modulate = true
appender.rolling.policies.size.type = SizeBasedTriggeringPolicy
appender.rolling.policies.size.size = 128MB
appender.rolling.strategy.type = DefaultRolloverStrategy
appender.rolling.strategy.fileIndex = nomax
appender.rolling.strategy.action.type = Delete
appender.rolling.strategy.action.basepath = ${sys:es.logs.base_path}
appender.rolling.strategy.action.condition.type = IfFileName
appender.rolling.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*
appender.rolling.strategy.action.condition.nested_condition.type = IfLastModified
appender.rolling.strategy.action.condition.nested_condition.age = 7D

```

It's the same parameter as [the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/logging.html)  
but it's not working.  
What is wrong ?

I don't know the logstash version, what should I do ?

1. add this parameter :  
`appender.rolling.strategy.delete.ifLastModified.age = 30d` instead of  
`appender.rolling.strategy.action.condition.nested_condition.age = 7D`

2. add this one :

```auto
appender.rolling.strategy.action.condition.nested_condition.lastMod.age = 30D

```

or another option ?

what is the good option in order to keep 30 days of logs ?

thank you for your help.

---

<div class="post-metadata">

**Author:** ![Ludovic9](https://avatars.discourse-cdn.com/v4/letter/l/977dab/32.png) [@Ludovic9](https://discuss.elastic.co/u/Ludovic9)\
**Post date:** [December 1, 2022, 3:45pm UTC](https://discuss.elastic.co/t/delete-old-logs-files/318317/2 "2022-12-01T15:45:06Z")

</div>

Hi any idea about this ?  
How I can have a deletion of those files \*-1.log.gz in order to have the last 30 days ?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [December 1, 2022, 6:11pm UTC](https://discuss.elastic.co/t/delete-old-logs-files/318317/3 "2022-12-01T18:11:15Z")

</div>

I use cron job to delete them on linux system. once a day.

/usr/bin/find /elastic/log/elasticsearch/ -mtime +30 -name "\*.gz" -exec rm -f {} ;

---

<div class="post-metadata">

**Author:** ![Ludovic9](https://avatars.discourse-cdn.com/v4/letter/l/977dab/32.png) [@Ludovic9](https://discuss.elastic.co/u/Ludovic9)\
**Post date:** [December 2, 2022, 11:14am UTC](https://discuss.elastic.co/t/delete-old-logs-files/318317/4 "2022-12-02T11:14:52Z")

</div>

Hi,  
the documentation says this :

> Elastic strongly recommends using the Log4j 2 configuration that is shipped by default.

> **[Logging | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/logging.html#loggin-configuration)**

but it's not working, even in 8.5 version 🙄

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2022, 11:15am UTC](https://discuss.elastic.co/t/delete-old-logs-files/318317/5 "2022-12-30T11:15:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
