# How to test log rolling and deletion in elasticsearch with log4j2.properties?

**URL:** <https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117>\
**Category:** Elasticsearch\
**Created:** [January 11, 2018, 3:15pm UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117 "2018-01-11T15:15:58Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sonfrau](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@sonfrau](https://discuss.elastic.co/u/sonfrau)\
**Post date:** [January 11, 2018, 3:15pm UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117/1 "2018-01-11T15:15:58Z")

</div>

Hello,  
We're using ES 6.1.1.  
We want to delete logs which matching whatever of these two conditions: size and age.  
For that, we have changed log4j2.properties file such as:

> appender.rolling.strategy.type = DefaultRolloverStrategy  
> appender.rolling.strategy.fileIndex = nomax  
> appender.rolling.strategy.action.type = Delete  
> appender.rolling.strategy.action.basepath = ${sys:es.logs.base\_path}  
> appender.rolling.strategy.action.condition.type = IfFileName  
> appender.rolling.strategy.action.condition.glob = ${sys:es.logs.cluster\_name}-\*  
> **\> appender.rolling.strategy.action.condition.nested\_condition.type = IfAny**  
> **\> appender.rolling.strategy.action.condition.nested\_condition.type = IfAccumulatedFileSize**  
> **\> appender.rolling.strategy.action.condition.nested\_condition.exceeds = 2GB**  
> **\> appender.rolling.strategy.action.condition.nested\_condition.type = IfLastModified**  
> **\> appender.rolling.strategy.action.condition.nested\_condition.age = 7D**

How could we test those changes?

Thanks and kind regards

---

<div class="post-metadata">

**Author:** ![s1monw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s1monw/32/3637_2.png) [@s1monw](https://discuss.elastic.co/u/s1monw)\
**Post date:** [January 19, 2018, 1:44pm UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117/2 "2018-01-19T13:44:23Z")

</div>

I would just make the numbers smaller and run es with trace log so you can see if these are applied?

---

<div class="post-metadata">

**Author:** ![sonfrau](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@sonfrau](https://discuss.elastic.co/u/sonfrau)\
**Post date:** [January 23, 2018, 4:33pm UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117/3 "2018-01-23T16:33:25Z")

</div>

Good afternoon s1monw,

thanks for your reply but I must say I have logs older than 7days and grearter than 2Gb. So I have files accomplishing the needed conditions to be deleted, however, I haven't seen any change in last 10 days.

I can say I have changed logge debugger level with this command:

> PUT /\_cluster/settings  
> {"transient":{"logger.\_root":"TRACE"}}

and unexpectedly for me, I could see how logger deleted log files older than 7 days and greater then 2Gb but I don't know neither how nor why.

Later, I created new fake log files older than 7 days and greater then 2Gb I changed

> PUT /\_cluster/settings  
> {"transient":{"logger.\_root":"ERROR"}}

No change. I changed log level over to:

> PUT /\_cluster/settings  
> {"transient":{"logger.\_root":"TRACE"}}

but no change.

So that to say I don't understand how ES logger works and how test it to check the changes on log4j2.properties.

Any clue will be welcome.

Thanks and regards

---

<div class="post-metadata">

**Author:** ![sonfrau](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@sonfrau](https://discuss.elastic.co/u/sonfrau)\
**Post date:** [January 23, 2018, 4:51pm UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117/4 "2018-01-23T16:51:56Z")

</div>

> $ sudo ls -laht /var/log/elasticsearch/\*  
> ...3.3G Jan 15 09:09 /var/log/elasticsearch/XTG\_ElasticStatic-2018-01-13-1.log.gz  
> ... 17K Jan 12 10:47 /var/log/elasticsearch/XTG\_ElasticStatic.log  
> ...4.6K Jan 12 10:47 /var/log/elasticsearch/XTG\_ElasticStatic-2018-01-11-1.log.gz  
> ...1.9K Jan 11 12:21 /var/log/elasticsearch/XTG\_ElasticStatic-2018-01-10-1.log.gz  
> ...3.1K Jan 10 10:07 /var/log/elasticsearch/XTG\_ElasticStatic-2018-01-08-1.log.gz  
> ...3.2K Jan 8 13:04 /var/log/elasticsearch/XTG\_ElasticStatic-2017-12-22-1.log.gz  
> ...3.3G Jan 1 09:05 /var/log/elasticsearch/XTG\_ElasticStatic-2017-12-28-1.log.gz  
> ... 350 Dec 25 09:11 /var/log/elasticsearch/XTG\_ElasticStatic-2017-12-13-1.log.gz  
> ... 0 Dec 22 12:24 /var/log/elasticsearch/XTG\_ElasticStatic\_index\_indexing\_slowlog.log  
> ... 0 Dec 22 12:24 /var/log/elasticsearch/XTG\_ElasticStatic\_index\_search\_slowlog.log  
> ... 0 Dec 22 12:24 /var/log/elasticsearch/XTG\_ElasticStatic\_deprecation.log

**$ [HERE WE HAVE CHANGED LOGGER DEBUGGER LEVEL TO "TRACE" AND SUBSEQUENTLY WE GOT THIS OUTPUT]**

> $ sudo ls -laht /var/log/elasticsearch/\*  
> ... 95K Jan 23 17:11 /var/log/elasticsearch/XTG\_ElasticStatic.log  
> ...1.3K Jan 23 17:10 /var/log/elasticsearch/XTG\_ElasticStatic-2018-01-12-1.log.gz  
> ... 0 Dec 22 12:24 /var/log/elasticsearch/XTG\_ElasticStatic\_index\_indexing\_slowlog.log  
> ... 0 Dec 22 12:24 /var/log/elasticsearch/XTG\_ElasticStatic\_index\_search\_slowlog.log  
> ... 0 Dec 22 12:24 /var/log/elasticsearch/XTG\_ElasticStatic\_deprecation.log  
> **[ES LOGGER DELETED LOGS OLDER THAN 7DAYS AND GREATER 2GB BUT WE HAVE NOT BEEN ABLE TO REPRODUCE IT AGAIN]**

---

<div class="post-metadata">

**Author:** ![sonfrau](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@sonfrau](https://discuss.elastic.co/u/sonfrau)\
**Post date:** [January 24, 2018, 8:47am UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117/5 "2018-01-24T08:47:39Z")

</div>

This morning, I have caused a change on Logger Debugger Level to TRACE and I have seen the Delete Policy working again successfully but I don't know how to reproduce it without having to wait 24 hours to see it again.

I have tried to delete ${sys:es.logs.cluster\_name}.log file but it didn't work.

Does anyone has any clue how could I test this log rolling and deletion with log4j2.properties?

Thanks

---

<div class="post-metadata">

**Author:** ![sonfrau](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@sonfrau](https://discuss.elastic.co/u/sonfrau)\
**Post date:** [January 31, 2018, 9:41am UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117/6 "2018-01-31T09:41:05Z")

</div>

Good morning,

Does anyone know if it's possible to add two or more conditions on log4j2.properties?

Thanks and kind regards

---

<div class="post-metadata">

**Author:** ![sonfrau](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@sonfrau](https://discuss.elastic.co/u/sonfrau)\
**Post date:** [February 15, 2018, 7:25am UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117/7 "2018-02-15T07:25:51Z")

</div>

We are not getting any answer about this issue  
Would you advise me to ask this discussion in other forum?  
Could you recommend which one?  
Thanks and kind regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2018, 7:25am UTC](https://discuss.elastic.co/t/how-to-test-log-rolling-and-deletion-in-elasticsearch-with-log4j2-properties/115117/8 "2018-03-15T07:25:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
