# Help setting up logging

**URL:** <https://discuss.elastic.co/t/help-setting-up-logging/16510>\
**Category:** Elasticsearch\
**Created:** [March 21, 2014, 1:05am UTC](https://discuss.elastic.co/t/help-setting-up-logging/16510 "2014-03-21T01:05:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raphael\_Miranda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphael_miranda/32/1709_2.png) [@Raphael\_Miranda](https://discuss.elastic.co/u/Raphael_Miranda)\
**Post date:** [March 21, 2014, 1:05am UTC](https://discuss.elastic.co/t/help-setting-up-logging/16510/1 "2014-03-21T01:05:58Z")

</div>

ES is creating the log files upon startup but they are empty? I switched  
every log level to DEBUG and it started pouring more log into  
elasticsearch.log still, no query or indexing is logged.

-rw-r--r-- 1 elasticsearch elasticsearch 0 Mar 21 00:54  
elasticsearch\_index\_indexing\_slowlog.log  
-rw-r--r-- 1 elasticsearch elasticsearch 0 Mar 21 00:54  
elasticsearch\_index\_search\_slowlog.log  
-rw-r--r-- 1 elasticsearch elasticsearch 83910 Mar 21 01:00  
elasticsearch.log

Heres my logging.yml

# you can override this using by setting a system property, for example

-Des.logger.level=DEBUG  
es.logger.level: DEBUG  
rootLogger: ${es.logger.level}, console, file  
logger:

# log action execution errors for easier debugging

action: DEBUG

# reduce the logging for aws, too much is logged under the default INFO

com.amazonaws: DEBUG

# gateway

gateway: DEBUG  
index.gateway: DEBUG

# peer shard recovery

indices.recovery: DEBUG

# discovery

discovery: DEBUG

index.search.slowlog: DEBUG, index\_search\_slow\_log\_file  
index.indexing.slowlog: DEBUG, index\_indexing\_slow\_log\_file

additivity:  
index.search.slowlog: true  
index.indexing.slowlog: true  
appender:  
console:  
type: console  
layout:  
type: consolePattern  
conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"

file:  
type: dailyRollingFile  
file: ${path.logs}/${cluster.name}.log  
datePattern: "'.'yyyy-MM-dd"  
layout:  
type: pattern  
conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"

index\_search\_slow\_log\_file:  
type: dailyRollingFile  
file: ${path.logs}/${cluster.name}\_index\_search\_slowlog.log  
datePattern: "'.'yyyy-MM-dd"  
layout:  
type: pattern  
conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"

index\_indexing\_slow\_log\_file:  
type: dailyRollingFile  
file: ${path.logs}/${cluster.name}\_index\_indexing\_slowlog.log  
datePattern: "'.'yyyy-MM-dd"  
layout:  
type: pattern  
conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [March 21, 2014, 1:56am UTC](https://discuss.elastic.co/t/help-setting-up-logging/16510/2 "2014-03-21T01:56:36Z")

</div>

The logging configuration specifies how and what to log, but it does not  
specify when or what actually constitutes a slow query/index. Not all  
queries/index requests are logged, just the slow ones. You need to define  
the threshold in the main elasticsearch.yml config file.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

--  
Ivan

On Thu, Mar 20, 2014 at 6:05 PM, Raphael Miranda  
[raphaelmiranda@gmail.com](mailto:raphaelmiranda@gmail.com)wrote:

> ES is creating the log files upon startup but they are empty? I switched  
> every log level to DEBUG and it started pouring more log into  
> elasticsearch.log still, no query or indexing is logged.
> 
> -rw-r--r-- 1 elasticsearch elasticsearch 0 Mar 21 00:54  
> elasticsearch\_index\_indexing\_slowlog.log  
> -rw-r--r-- 1 elasticsearch elasticsearch 0 Mar 21 00:54  
> elasticsearch\_index\_search\_slowlog.log  
> -rw-r--r-- 1 elasticsearch elasticsearch 83910 Mar 21 01:00  
> elasticsearch.log
> 
> Heres my logging.yml
> 
> # you can override this using by setting a system property, for example
> 
> -Des.logger.level=DEBUG  
> es.logger.level: DEBUG  
> rootLogger: ${es.logger.level}, console, file  
> logger:
> 
> # log action execution errors for easier debugging
> 
> action: DEBUG
> 
> # reduce the logging for aws, too much is logged under the default INFO
> 
> com.amazonaws: DEBUG
> 
> # gateway
> 
> gateway: DEBUG  
> index.gateway: DEBUG
> 
> # peer shard recovery
> 
> indices.recovery: DEBUG
> 
> # discovery
> 
> discovery: DEBUG
> 
> index.search.slowlog: DEBUG, index\_search\_slow\_log\_file  
> index.indexing.slowlog: DEBUG, index\_indexing\_slow\_log\_file
> 
> additivity:  
> index.search.slowlog: true  
> index.indexing.slowlog: true  
> appender:  
> console:  
> type: console  
> layout:  
> type: consolePattern  
> conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
> 
> file:  
> type: dailyRollingFile  
> file: ${path.logs}/${cluster.name}.log  
> datePattern: "'.'yyyy-MM-dd"  
> layout:  
> type: pattern  
> conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
> 
> index\_search\_slow\_log\_file:  
> type: dailyRollingFile  
> file: ${path.logs}/${cluster.name}\_index\_search\_slowlog.log  
> datePattern: "'.'yyyy-MM-dd"  
> layout:  
> type: pattern  
> conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
> 
> index\_indexing\_slow\_log\_file:  
> type: dailyRollingFile  
> file: ${path.logs}/${cluster.name}\_index\_indexing\_slowlog.log  
> datePattern: "'.'yyyy-MM-dd"  
> layout:  
> type: pattern  
> conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQBwy\_yL\_wif20GNtk3z\_B%3Djt2%2BQCxxjQ-CCPh4WX9mqdw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CALY%3DcQBwy_yL_wif20GNtk3z_B%3Djt2%2BQCxxjQ-CCPh4WX9mqdw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Raphael\_Miranda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raphael_miranda/32/1709_2.png) [@Raphael\_Miranda](https://discuss.elastic.co/u/Raphael_Miranda)\
**Post date:** [March 21, 2014, 5:30pm UTC](https://discuss.elastic.co/t/help-setting-up-logging/16510/3 "2014-03-21T17:30:54Z")

</div>

Thank you very much.

I figured the name slowlog meant it was verbose and not directives to log  
actions that surpass a given threshold. I lowered the config to 1ms and now  
I can see the logs.

On Thursday, 20 March 2014 22:56:36 UTC-3, Ivan Brusic wrote:

> The logging configuration specifies how and what to log, but it does not  
> specify when or what actually constitutes a slow query/index. Not all  
> queries/index requests are logged, just the slow ones. You need to define  
> the threshold in the main elasticsearch.yml config file.
> 
> [Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/index-modules-slowlog.html)
> 
> --  
> Ivan
> 
> On Thu, Mar 20, 2014 at 6:05 PM, Raphael Miranda \<[raphael...@gmail.com](mailto:raphael...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > ES is creating the log files upon startup but they are empty? I switched  
> > every log level to DEBUG and it started pouring more log into  
> > elasticsearch.log still, no query or indexing is logged.
> > 
> > -rw-r--r-- 1 elasticsearch elasticsearch 0 Mar 21 00:54  
> > elasticsearch\_index\_indexing\_slowlog.log  
> > -rw-r--r-- 1 elasticsearch elasticsearch 0 Mar 21 00:54  
> > elasticsearch\_index\_search\_slowlog.log  
> > -rw-r--r-- 1 elasticsearch elasticsearch 83910 Mar 21 01:00  
> > elasticsearch.log
> > 
> > Heres my logging.yml
> > 
> > # you can override this using by setting a system property, for example
> > 
> > -Des.logger.level=DEBUG  
> > es.logger.level: DEBUG  
> > rootLogger: ${es.logger.level}, console, file  
> > logger:
> > 
> > # log action execution errors for easier debugging
> > 
> > action: DEBUG
> > 
> > # reduce the logging for aws, too much is logged under the default INFO
> > 
> > com.amazonaws: DEBUG
> > 
> > # gateway
> > 
> > gateway: DEBUG  
> > index.gateway: DEBUG
> > 
> > # peer shard recovery
> > 
> > indices.recovery: DEBUG
> > 
> > # discovery
> > 
> > discovery: DEBUG
> > 
> > index.search.slowlog: DEBUG, index\_search\_slow\_log\_file  
> > index.indexing.slowlog: DEBUG, index\_indexing\_slow\_log\_file
> > 
> > additivity:  
> > index.search.slowlog: true  
> > index.indexing.slowlog: true  
> > appender:  
> > console:  
> > type: console  
> > layout:  
> > type: consolePattern  
> > conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
> > 
> > file:  
> > type: dailyRollingFile  
> > file: ${path.logs}/${cluster.name}.log  
> > datePattern: "'.'yyyy-MM-dd"  
> > layout:  
> > type: pattern  
> > conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
> > 
> > index\_search\_slow\_log\_file:  
> > type: dailyRollingFile  
> > file: ${path.logs}/${cluster.name}\_index\_search\_slowlog.log  
> > datePattern: "'.'yyyy-MM-dd"  
> > layout:  
> > type: pattern  
> > conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
> > 
> > index\_indexing\_slow\_log\_file:  
> > type: dailyRollingFile  
> > file: ${path.logs}/${cluster.name}\_index\_indexing\_slowlog.log  
> > datePattern: "'.'yyyy-MM-dd"  
> > layout:  
> > type: pattern  
> > conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/39a035f9-752c-47a5-9a5c-61d4aeb643ee%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/41599209-093b-40d9-890b-90071d4c17e8%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/41599209-093b-40d9-890b-90071d4c17e8%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41am UTC](https://discuss.elastic.co/t/help-setting-up-logging/16510/4 "2017-07-06T01:41:32Z")

</div>


