# How to collect elasticsearch logs in docker

**URL:** <https://discuss.elastic.co/t/how-to-collect-elasticsearch-logs-in-docker/207448>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [November 12, 2019, 6:43am UTC](https://discuss.elastic.co/t/how-to-collect-elasticsearch-logs-in-docker/207448 "2019-11-12T06:43:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Petr.Simik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/petr.simik/32/38082_2.png) [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Post date:** [November 12, 2019, 6:43am UTC](https://discuss.elastic.co/t/how-to-collect-elasticsearch-logs-in-docker/207448/1 "2019-11-12T06:43:36Z")

</div>

I need to access elasticsearch logs of elasticsearch cluster running within docker containers.  
Volumes: - /mnt/ssd1/eslog1:/var/log/elasticsearch  
is not the option , all logs are by default send to stdout and accessible only via

> docker logs es-node21

How I can access the logs,  
I am thinking of filebeat elasticsearch module to collect the logs into elasticsearch.

This is my docker-compose.yml

> version: '3.3'  
> services:  
> es-node21:  
> image: [docker.elastic.co/elasticsearch/elasticsearch:7.4.2](http://docker.elastic.co/elasticsearch/elasticsearch:7.4.2)  
> container\_name: es-node21  
> restart: always  
> environment:  
> - node.name=es-node21  
> - "discovery.zen.ping.unicast.hosts=node3.corp,node2.corp"  
> - http.cors.enabled=true  
> - http.cors.allow-origin=\*  
> - cluster.name=cem-docker-cluster  
> - bootstrap.memory\_lock=true  
> - "ES\_JAVA\_OPTS=-Xms24g -Xmx24g"  
> ulimits:  
> memlock:  
> soft: -1  
> hard: -1  
> volumes:  
> - /mnt/ssd1/esdata1:/usr/share/elasticsearch/data  
> - /mnt/ssd1/eslog1:/var/log/elasticsearch --- this logging does not work need to be done another way!!  
> ports:  
> - 9200:9200  
> - 9300:9300  
> deploy:  
> resources:  
> limits:  
> cpus: '12'  
> network\_mode: host

---

<div class="post-metadata">

**Author:** ![MiTschMR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mitschmr/32/48254_2.png) [@MiTschMR](https://discuss.elastic.co/u/MiTschMR)\
**Post date:** [November 12, 2019, 7:15am UTC](https://discuss.elastic.co/t/how-to-collect-elasticsearch-logs-in-docker/207448/2 "2019-11-12T07:15:00Z")

</div>

Hi @Petr.Simik

To get Elasticsearch write the logs to file you either need to do some hacky stuff with docker and the command parameters or modify the log4j2.properties file. I advise you to check out the following site:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/logging.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/logging.html)

You need to map the new log4j2.properties to the containers and also need a folder mapped into the directory you want to save the logs.

Hope this leads you on the right way.

---

<div class="post-metadata">

**Author:** ![Petr.Simik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/petr.simik/32/38082_2.png) [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Post date:** [November 29, 2019, 8:50am UTC](https://discuss.elastic.co/t/how-to-collect-elasticsearch-logs-in-docker/207448/3 "2019-11-29T08:50:02Z")

</div>

@MiTschMR thank you this definitely leads to the solution, I had not time to test it , but I belive this is the solution. Thank u

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2019, 8:50am UTC](https://discuss.elastic.co/t/how-to-collect-elasticsearch-logs-in-docker/207448/4 "2019-12-27T08:50:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
