# Docker Logstash internal logging to file?

**URL:** <https://discuss.elastic.co/t/docker-logstash-internal-logging-to-file/206951>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [November 7, 2019, 10:58am UTC](https://discuss.elastic.co/t/docker-logstash-internal-logging-to-file/206951 "2019-11-07T10:58:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sam.brooks](https://avatars.discourse-cdn.com/v4/letter/s/9f8e36/32.png) [@sam.brooks](https://discuss.elastic.co/u/sam.brooks)\
**Post date:** [November 7, 2019, 10:58am UTC](https://discuss.elastic.co/t/docker-logstash-internal-logging-to-file/206951/1 "2019-11-07T10:58:44Z")

</div>

I'm having a similar problem as two posters before me, whose posts did not get resolved:

> [@How to make Logstash write internal logs to a file? (--path.logs fails)](https://discuss.elastic.co/t/how-to-make-logstash-write-internal-logs-to-a-file-path-logs-fails/126822):
>
> Context I am building a program that will pass an Apache log file into Logstash and output the result (after parsing and filtering) to an external database (Elastic, MongoDB, etc.). Basically, the program will execute following command: gunzip -c -k "somefile.gz" | logstash -f "logstash.conf" With logstash.conf containing: input { stdin {} } filter { # ... } output { mongodb { # ... } } But, to help future debug/forensic, I want to grab whatever Logstash says during …

> [@Where are the internal logstash logs when run in a Docker container?](https://discuss.elastic.co/t/where-are-the-internal-logstash-logs-when-run-in-a-docker-container/194623):
>
> Where are the internal Logstash logs? Docs state, " Logstash emits internal logs during its operation, which are placed in LS\_HOME/logs (or /var/log/logstash for DEB/RPM)." [Ref 1] When I open a shell into the container, I do not see these logs; they do not exist. I'm trying to debug some setup errors. How can I grep and view internal logstash logs? [https://www.elastic.co/guide/en/logstash/current/logging.html](https://www.elastic.co/guide/en/logstash/current/logging.html)

I am hoping that this time, we can find a solution.

I am using the Logstash docker container ([docker.elastic.co/logstash/logstash:7.1.1](http://docker.elastic.co/logstash/logstash:7.1.1)).  
I can see the internal logging just fine by running:  
`docker logs -f logstash`  
However, I need the internal logging to be saved to file inside the docker container, for various reasons.

Since there is no log4j.properties file in the logstash docker container by default, I have created the following log4j.properties file and placed it in the container's /etc/logstash AND /usr/share/logstash/config (since there is conflicting information online about where to put this file):

```
# Root logger option
log4j.rootLogger=INFO, file, stdout

# Direct log messages to a log file
log4j.appender.file=org.apache.log4j.RollingFileAppender
log4j.appender.file.File=/var/log/logstash/logging.log
log4j.appender.file.MaxFileSize=10MB
log4j.appender.file.MaxBackupIndex=10
log4j.appender.file.layout=org.apache.log4j.PatternLayout
log4j.appender.file.layout.ConversionPattern=%d{yyyy-MM-dd HH:mm:ss} %-5p %c{1}:%L - %m%n

# Direct log messages to stdout
log4j.appender.stdout=org.apache.log4j.ConsoleAppender
log4j.appender.stdout.Target=System.out
log4j.appender.stdout.layout=org.apache.log4j.PatternLayout
log4j.appender.stdout.layout.ConversionPattern=%d{yyyy-MM-dd HH:mm:ss} %-5p %c{1}:%L - %m%n

```

I based the above log4j.properties file on the one specified in this page, since it seemed like it would suit my needs:

> **[log4j.properties example - Mkyong.com](https://mkyong.com/logging/log4j-log4j-properties-examples/)**
>
> \- log4j.properties example

After restarting the container, the internal logging still does not appear in files in /var/log/logstash/

I am aware that there may also be a solution to do with appending parameters when running logstash initially, but since logstash starts automatically when creating/running the logstash docker container, I'm not sure if that's a feasible solution in this case.

Could anyone point out what I am doing wrong? How can we get internal logging to files when running the standard logstash docker container?

---

<div class="post-metadata">

**Author:** ![sam.brooks](https://avatars.discourse-cdn.com/v4/letter/s/9f8e36/32.png) [@sam.brooks](https://discuss.elastic.co/u/sam.brooks)\
**Post date:** [November 7, 2019, 4:41pm UTC](https://discuss.elastic.co/t/docker-logstash-internal-logging-to-file/206951/2 "2019-11-07T16:41:19Z")

</div>

After a more careful look at the logstash internal logs, it looks like it was looking for '/usr/share/logstash/config/log4j2.properties'.

After renaming the .properties file to include the '2', the internal logs now say:  
`Sending Logstash logs to /var/log/logstash which is now configured via log4j2.properties`  
However, the log files are not appearing in /var/log/logstash. I've used chmod to give full accessibility to this folder in case logstash simply didn't have the permissions to write files in this folder, but that doesn't seem to help.

---

<div class="post-metadata">

**Author:** ![kmiklas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmiklas/32/50730_2.png) [@kmiklas](https://discuss.elastic.co/u/kmiklas)\
**Post date:** [November 8, 2019, 3:20pm UTC](https://discuss.elastic.co/t/docker-logstash-internal-logging-to-file/206951/3 "2019-11-08T15:20:25Z")

</div>

I've been looking at

**/var/log/logstash/logstash-plain.log**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2019, 3:20pm UTC](https://discuss.elastic.co/t/docker-logstash-internal-logging-to-file/206951/4 "2019-12-06T15:20:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
