# How to set Log4J level on individual Logstash plugin?

**URL:** <https://discuss.elastic.co/t/how-to-set-log4j-level-on-individual-logstash-plugin/74306>\
**Category:** Logstash\
**Created:** [February 8, 2017, 1:13am UTC](https://discuss.elastic.co/t/how-to-set-log4j-level-on-individual-logstash-plugin/74306 "2017-02-08T01:13:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Defaux](https://avatars.discourse-cdn.com/v4/letter/d/f14d63/32.png) [@Defaux](https://discuss.elastic.co/u/Defaux)\
**Post date:** [February 8, 2017, 1:13am UTC](https://discuss.elastic.co/t/how-to-set-log4j-level-on-individual-logstash-plugin/74306/1 "2017-02-08T01:13:29Z")

</div>

Background: I've been working extensively with the Logstash Netflow codec the past few days. Although it's been working fairly well, it's been filling my logs with a ton of messages like:

```auto
...
[2017-02-08T00:52:58,724][WARN][logstash.codecs.netflow] Ignoring Netflow version v10
[2017-02-08T00:52:58,724][WARN][logstash.codecs.netflow] Ignoring Netflow version v10
[2017-02-08T00:52:58,724][WARN][logstash.codecs.netflow] Ignoring Netflow version v10
...

```

(I am ignoring v10 on purpose, and cannot turn off those messages)

These logs are becoming a problem due to:

- The excessive amount of disk space used by the log files
- The drain on computer resources as it writes the excessive amount of warning messages to disk.

What I'd ultimately like to do is instruct Log4J to only log the Netflow codec plugin's messages when they are ERROR+. **But** still see INFO+ messages from other plugins/logstash core.

Is there a way to set configuration for a specific plugin's logger? At the moment I have a pretty standard `log4j2.properties` (I assume taken from some arbitrary example):

```java
appender.rolling.policies.type = Policies
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.rolling.policies.time.interval = 1
appender.rolling.policies.time.modulate = true
appender.rolling.layout.type = PatternLayout
appender.rolling.layout.pattern = [%d{ISO8601}][%-5p][%-25c] %-.10000m%n

appender.json_rolling.type = RollingFile
appender.json_rolling.name = json_rolling
appender.json_rolling.fileName = ${sys:ls.logs}/logstash-${sys:ls.log.format}.log
appender.json_rolling.filePattern = ${sys:ls.logs}/logstash-${sys:ls.log.format}-%d{yyyy-MM-dd}.log
appender.json_rolling.policies.type = Policies
appender.json_rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.json_rolling.policies.time.interval = 1
appender.json_rolling.policies.time.modulate = true
appender.json_rolling.layout.type = JSONLayout
appender.json_rolling.layout.compact = true
appender.json_rolling.layout.eventEol = true

rootLogger.level = ${sys:ls.log.level}
rootLogger.appenderRef.rolling.ref = ${sys:ls.log.format}_rolling

```

---

<div class="post-metadata">

**Author:** ![Defaux](https://avatars.discourse-cdn.com/v4/letter/d/f14d63/32.png) [@Defaux](https://discuss.elastic.co/u/Defaux)\
**Post date:** [February 8, 2017, 11:42pm UTC](https://discuss.elastic.co/t/how-to-set-log4j-level-on-individual-logstash-plugin/74306/2 "2017-02-08T23:42:26Z")

</div>

Got it!

First, a co-worker pointed out that Logstash 5's HTTP API has some documentation around getting or setting log levels: [https://www.elastic.co/guide/en/logstash/current/logging.html](https://www.elastic.co/guide/en/logstash/current/logging.html)

So after a bit of RTFM, looks like we can dynamically set log levels on a plugin-level basis! But it's an ephemeral setting - I needed something more permanent.

I found adding the following to the bottom of my `log4j2.properties` does the trick:

```auto
logger.netflow.name = logstash.codecs.netflow
logger.netflow.level = ERROR

```

This plugin is now blissfully silent.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2017, 11:42pm UTC](https://discuss.elastic.co/t/how-to-set-log4j-level-on-individual-logstash-plugin/74306/3 "2017-03-08T23:42:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
