# Elaseticsearch logs filling up very fast

**URL:** <https://discuss.elastic.co/t/elaseticsearch-logs-filling-up-very-fast/70274>\
**Category:** Elasticsearch\
**Created:** [December 30, 2016, 1:42pm UTC](https://discuss.elastic.co/t/elaseticsearch-logs-filling-up-very-fast/70274 "2016-12-30T13:42:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkumar](https://avatars.discourse-cdn.com/v4/letter/p/87869e/32.png) [@pkumar](https://discuss.elastic.co/u/pkumar)\
**Post date:** [December 30, 2016, 1:42pm UTC](https://discuss.elastic.co/t/elaseticsearch-logs-filling-up-very-fast/70274/1 "2016-12-30T13:42:28Z")

</div>

HI Team,

My Elastic Search logs are filling up very fast and need some help rotating the logs.

My config is set to the location - /usr/local/etc/elasticsearch/elasticsearch.yml, where paths are set as below  
path.conf: /usr/local/etc/elasticsearch  
path.data: /data/elasticsearch  
path.logs: /usr/local/var/log/elasticsearch

How can the update this yml file to rotate the logs based on file size so that it gets rotated and cause no disk space issues.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [December 30, 2016, 2:22pm UTC](https://discuss.elastic.co/t/elaseticsearch-logs-filling-up-very-fast/70274/2 "2016-12-30T14:22:08Z")

</div>

In 5.0+ you can update log4j2.properties to change `appender.rolling` to look more like `appender.deprecation_rolling`. In 2.x I believe it is possible but I've forgotten how. The first thing to check is to see if you have log4j extras in the lib directory. If so you should be able set it up but it'll take some googling to find someone that's done it. I haven't but I remember seeing it somewhere.

As to the logs filling up fast, that is usually some other problem. It'd be nice to track that down as well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2017, 2:22pm UTC](https://discuss.elastic.co/t/elaseticsearch-logs-filling-up-very-fast/70274/3 "2017-01-27T14:22:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
