# Elasticsearch 1.7 logrotation crashes for clusters with low logging

**URL:** https://discuss.elastic.co/t/elasticsearch-1-7-logrotation-crashes-for-clusters-with-low-logging/216017
**Category:** Elasticsearch
**Created:** [January 22, 2020, 9:27am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-logrotation-crashes-for-clusters-with-low-logging/216017 "2020-01-22T09:27:59Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![workaround](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/workaround/32/48152_2.png) [@workaround](https://discuss.elastic.co/u/workaround)
#### Post date: [January 22, 2020, 9:27am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-logrotation-crashes-for-clusters-with-low-logging/216017/1 "2020-01-22T09:27:59Z")

</div>

Hello,

We have specific active Elasticsearch clusters whose logrotation crushes frequently.

We have more than 100 elasticsearch clusters and just some specific keep crushing their logrotation.  
After investigation, I have come to conclude that it has something to do with the small amount of logging to those clusters. Some days there are no logs to those clusters.

I have two suspects:

1. either log4j.properties minimum size, which I could not locate ( as a file ) somewhere in the installation. Thus I wonder wether it is overriden by something or has some kind of defaults if not present.

2. The conversion pattern of the logs which looks something like this:

**log4j or logging.yml?**

Thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 19, 2020, 9:35am UTC](https://discuss.elastic.co/t/elasticsearch-1-7-logrotation-crashes-for-clusters-with-low-logging/216017/2 "2020-02-19T09:35:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
