# Elastic Search Logs Retention

**URL:** <https://discuss.elastic.co/t/elastic-search-logs-retention/23998>\
**Category:** Elasticsearch\
**Created:** [June 19, 2015, 2:54pm UTC](https://discuss.elastic.co/t/elastic-search-logs-retention/23998 "2015-06-19T14:54:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sagarshah1983](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagarshah1983/32/3403_2.png) [@sagarshah1983](https://discuss.elastic.co/u/sagarshah1983)\
**Post date:** [June 19, 2015, 2:54pm UTC](https://discuss.elastic.co/t/elastic-search-logs-retention/23998/1 "2015-06-19T14:54:42Z")

</div>

Hello everyone,  
I am using Elastic Search 1.4.2.  
We see that elastic search has it's own logging configuration file called logging.yml, which by default has daily file rolling appender.

Is there any configuration available in this file to keep only last 30 days of logs file and remove the older log files?

I tried **maxBackupIndex** (as suggested on certain blogs), but that resulted in following warning

Please suggest.

Appreciate!

Regards,  
Sagar Shah

---

<div class="post-metadata">

**Author:** ![sagarshah1983](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagarshah1983/32/3403_2.png) [@sagarshah1983](https://discuss.elastic.co/u/sagarshah1983)\
**Post date:** [June 23, 2015, 7:44pm UTC](https://discuss.elastic.co/t/elastic-search-logs-retention/23998/2 "2015-06-23T19:44:52Z")

</div>

Is there no setting in elastic search 1.4.2 to handle this log rotation/retention?  
I would be surprised to know that.

Regards,  
Sagar Shah

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 23, 2015, 7:50pm UTC](https://discuss.elastic.co/t/elastic-search-logs-retention/23998/3 "2015-06-23T19:50:08Z")

</div>

> [@sagarshah1983](#):
>
> I tried **maxBackupIndex** (as suggested on certain blogs), but that resulted in following warning

What warning? I believe you forgot to paste the error message.

---

<div class="post-metadata">

**Author:** ![sagarshah1983](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagarshah1983/32/3403_2.png) [@sagarshah1983](https://discuss.elastic.co/u/sagarshah1983)\
**Post date:** [June 23, 2015, 8:05pm UTC](https://discuss.elastic.co/t/elastic-search-logs-retention/23998/4 "2015-06-23T20:05:08Z")

</div>

Sorry about that.

I see following message when starting elastic search with maxBackupIndex property configured in logging.yml file.

log4j:WARN No such property [maxBackupIndex] in org.apache.log4j.DailyRollingFileAppender.

Here's the configuration snippet.

```
  file:
    type: dailyRollingFile
    file: ${path.logs}/${cluster.name}.log
    datePattern: "'.'yyyy-MM-dd"
    maxBackupIndex: 1
    layout:
      type: pattern
      conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 24, 2015, 6:06am UTC](https://discuss.elastic.co/t/elastic-search-logs-retention/23998/5 "2015-06-24T06:06:21Z")

</div>

[DailyRolllingFileAppender](https://logging.apache.org/log4j/1.2/apidocs/org/apache/log4j/DailyRollingFileAppender.html) doesn't have a maxBackupIndex configuration knob, it's [RollingFileAppender](https://logging.apache.org/log4j/1.2/apidocs/org/apache/log4j/RollingFileAppender.html) that has it. If you can't switch, consider using a custom appender (a quick googling indicated that there might be a few ones you can use) or add a simple cronjob that deletes old files.

---

<div class="post-metadata">

**Author:** ![sagarshah1983](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sagarshah1983/32/3403_2.png) [@sagarshah1983](https://discuss.elastic.co/u/sagarshah1983)\
**Post date:** [June 25, 2015, 7:14pm UTC](https://discuss.elastic.co/t/elastic-search-logs-retention/23998/6 "2015-06-25T19:14:18Z")

</div>

That helps!  
Appreciate your inputs!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:05am UTC](https://discuss.elastic.co/t/elastic-search-logs-retention/23998/7 "2017-07-06T00:05:21Z")

</div>


