# ElasticSearch log management

**URL:** <https://discuss.elastic.co/t/elasticsearch-log-management/18397>\
**Category:** Elasticsearch\
**Created:** [June 30, 2014, 3:02pm UTC](https://discuss.elastic.co/t/elasticsearch-log-management/18397 "2014-06-30T15:02:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![IronMike](https://avatars.discourse-cdn.com/v4/letter/i/e9a140/32.png) [@IronMike](https://discuss.elastic.co/u/IronMike)\
**Post date:** [June 30, 2014, 3:02pm UTC](https://discuss.elastic.co/t/elasticsearch-log-management/18397/1 "2014-06-30T15:02:24Z")

</div>

Does ElasticSearch roll logs? Does it create new log with different name  
everyday?  
I would like to know how to manage logs, I would like to keep last 10 days  
worth of logs, but not more that that, as they can be very big.  
Any ideas What Elasticsearch already does and what I need to do in order to  
manage logs?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [June 30, 2014, 5:51pm UTC](https://discuss.elastic.co/t/elasticsearch-log-management/18397/2 "2014-06-30T17:51:06Z")

</div>

Elasticsearch uses log4j for logging, so all logging configuration can be  
done via the log4j config file logging.xml

[https://github.com/elasticsearch/elasticsearch/blob/master/config/logging.yml](https://github.com/elasticsearch/elasticsearch/blob/master/config/logging.yml)

The default type is dailyRollingFile, which as the name states, rotates the  
log file daily.

--  
Ivan

On Mon, Jun 30, 2014 at 8:02 AM, IronMan2014 [sabdalla80@gmail.com](mailto:sabdalla80@gmail.com) wrote:

> Does Elasticsearch roll logs? Does it create new log with different name  
> everyday?  
> I would like to know how to manage logs, I would like to keep last 10 days  
> worth of logs, but not more that that, as they can be very big.  
> Any ideas What Elasticsearch already does and what I need to do in order  
> to manage logs?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQD2AV3Kk3iZbG8%3DCSGJ4PR074c2X\_Bin\_PvKppnJHh7GA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQD2AV3Kk3iZbG8%3DCSGJ4PR074c2X_Bin_PvKppnJHh7GA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [June 30, 2014, 6:02pm UTC](https://discuss.elastic.co/t/elasticsearch-log-management/18397/3 "2014-06-30T18:02:28Z")

</div>

On Mon, Jun 30, 2014 at 1:51 PM, Ivan Brusic [ivan@brusic.com](mailto:ivan@brusic.com) wrote:

> Elasticsearch uses log4j for logging, so all logging configuration can be  
> done via the log4j config file logging.xml
> 
> [https://github.com/elasticsearch/elasticsearch/blob/master/config/logging.yml](https://github.com/elasticsearch/elasticsearch/blob/master/config/logging.yml)
> 
> The default type is dailyRollingFile, which as the name states, rotates  
> the log file daily.

We need them deleted after the right amount of time so its easier for us to  
just let logrotate do everything:  
[http://git.wikimedia.org/blob/operations%2Fpuppet.git/production/modules%2Felasticsearch%2Ffiles%2Flogrotate](http://git.wikimedia.org/blob/operations%2Fpuppet.git/production/modules%2Felasticsearch%2Ffiles%2Flogrotate)  
[http://git.wikimedia.org/blob/operations%2Fpuppet.git/production/modules%2Felasticsearch%2Ftemplates%2Flogging.yml.erb](http://git.wikimedia.org/blob/operations%2Fpuppet.git/production/modules%2Felasticsearch%2Ftemplates%2Flogging.yml.erb)

That last one is an erb file so don't use it verbatim - just use it for  
inspiration if you need it.

Nik

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAPmjWd3LXqpE41xwL6fLgfqnGU%2BBKvn94kY-ktO13WRAdOeVBQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAPmjWd3LXqpE41xwL6fLgfqnGU%2BBKvn94kY-ktO13WRAdOeVBQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![IronMike](https://avatars.discourse-cdn.com/v4/letter/i/e9a140/32.png) [@IronMike](https://discuss.elastic.co/u/IronMike)\
**Post date:** [June 30, 2014, 6:17pm UTC](https://discuss.elastic.co/t/elasticsearch-log-management/18397/4 "2014-06-30T18:17:00Z")

</div>

Thanks, So do you keep all the logs? How do you delete old ones?

On Monday, June 30, 2014 1:51:13 PM UTC-4, Ivan Brusic wrote:

> Elasticsearch uses log4j for logging, so all logging configuration can be  
> done via the log4j config file logging.xml
> 
> [https://github.com/elasticsearch/elasticsearch/blob/master/config/logging.yml](https://github.com/elasticsearch/elasticsearch/blob/master/config/logging.yml)
> 
> The default type is dailyRollingFile, which as the name states, rotates  
> the log file daily.
> 
> --  
> Ivan
> 
> On Mon, Jun 30, 2014 at 8:02 AM, IronMan2014 \<[sabda...@gmail.com](mailto:sabda...@gmail.com)  
> \<javascript:\>\> wrote:
> 
> > Does Elasticsearch roll logs? Does it create new log with different name  
> > everyday?  
> > I would like to know how to manage logs, I would like to keep last 10  
> > days worth of logs, but not more that that, as they can be very big.  
> > Any ideas What Elasticsearch already does and what I need to do in order  
> > to manage logs?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/61f7ff1c-021e-4aa9-bffd-ba72a6837c37%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/c5ce353f-7275-40cc-b2bc-6a8376dbb091%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/c5ce353f-7275-40cc-b2bc-6a8376dbb091%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:18am UTC](https://discuss.elastic.co/t/elasticsearch-log-management/18397/5 "2017-07-06T01:18:51Z")

</div>


