# Log Deletion on Elasticsearch nodes based on lastModified

**URL:** <https://discuss.elastic.co/t/log-deletion-on-elasticsearch-nodes-based-on-lastmodified/322785>\
**Category:** Elasticsearch\
**Created:** [January 10, 2023, 5:30am UTC](https://discuss.elastic.co/t/log-deletion-on-elasticsearch-nodes-based-on-lastmodified/322785 "2023-01-10T05:30:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mahesh\_tangella](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mahesh_tangella/32/115743_2.png) [@mahesh\_tangella](https://discuss.elastic.co/u/mahesh_tangella)\
**Post date:** [January 10, 2023, 5:30am UTC](https://discuss.elastic.co/t/log-deletion-on-elasticsearch-nodes-based-on-lastmodified/322785/1 "2023-01-10T05:30:46Z")

</div>

Hello Team,

We are facing an issue with log deletion policy defined in log4j2.properties based on ifLastModified age. We want to delete all the log files which are larger than 2GB in size and older than 15 days.

So, we added the following properties to our log4j2.properties file on our existing Elasticsearch nodes.

```auto
appender.rolling.strategy.type = DefaultRolloverStrategy
appender.rolling.strategy.fileIndex = nomax
appender.rolling.strategy.action.type = Delete
appender.rolling.strategy.action.basepath = ${sys:es.logs.base_path}
appender.rolling.strategy.action.condition.type = IfFileName
appender.rolling.strategy.action.condition.glob = ${sys:es.logs.cluster_name}-*
appender.rolling.strategy.action.condition.nested_condition.type = IfAny
appender.rolling.strategy.action.condition.nested_condition.fileSize.type = IfAccumulatedFileSize
appender.rolling.strategy.action.condition.nested_condition.fileSize.exceeds = 2GB
appender.rolling.strategy.action.condition.nested_condition.lastMod.type = IfLastModified
appender.rolling.strategy.action.condition.nested_condition.lastMod.age = 15D

```

Upon restarting the Elasticsearch service on the nodes, all the log files which are larger than 2GB got deleted but the files older than 15Days don't get deleted. We even tried changing the lastModified condition to 2 days and waited for two days to check whether the files got deleted, but unfortunately no luck.

Can someone please suggest as to what's going wrong in the above configuration or any other alternatives we have, to delete log files after a certain limit is reached. This is crucial as we are running into disk space being full on Elasticsearch nodes.

Thanks,  
Mahesh

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2023, 5:31am UTC](https://discuss.elastic.co/t/log-deletion-on-elasticsearch-nodes-based-on-lastmodified/322785/2 "2023-02-07T05:31:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
