# Log Retention Issue - Only 10 Days of Logs Kept, Need Assistance

**URL:** <https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [July 26, 2023, 12:15pm UTC](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307 "2023-07-26T12:15:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![7a6b6f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/7a6b6f/32/118074_2.png) [@7a6b6f](https://discuss.elastic.co/u/7a6b6f)\
**Post date:** [July 26, 2023, 12:15pm UTC](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307/1 "2023-07-26T12:15:57Z")

</div>

Hi everyone,

I am facing an issue with log retention in my Elastic Stack setup and could use some help in troubleshooting it. Currently, my system is only retaining logs for 10 days, and after that, the logs are being deleted. I have checked several factors, including logrotate, crontab, and any external scripts that might be causing this behavior, but everything seems fine.

Here are some details about my environment:

- Elastic Version: 8.6.2
- Kibana Version: 8.6.2
- Logstash Version: 8.6.2
- Operating System: CentOS 8

My Logstash container configuration (docker-compose.yml):

```auto
  ...
  logstash:
    container_name: ip_logstash
    image: logstash:8.6.2
    ports:
      - '514:514/udp'
    environment:
      - xpack.monitoring.enabled= true
    volumes:
      - type: bind
        source: ./logstash/pipeline
        target: /usr/share/logstash/pipeline
        read_only: true
      - type: bind
        source: /tmp/devices_output_logs
        target: /var/log/syslog
        read_only: false
    ...

```

Any suggestions or insights into what might be causing the log retention issue would be highly appreciated. Has anyone encountered a similar problem or have any specific troubleshooting steps I can try?

Thank you in advance for your help!

Best regards

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 26, 2023, 12:41pm UTC](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307/2 "2023-07-26T12:41:36Z")

</div>

By logs you mean Elasticsearch indices or the logs from the services?

---

<div class="post-metadata">

**Author:** ![7a6b6f](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/7a6b6f/32/118074_2.png) [@7a6b6f](https://discuss.elastic.co/u/7a6b6f)\
**Post date:** [July 26, 2023, 1:16pm UTC](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307/3 "2023-07-26T13:16:23Z")

</div>

Thank you for your response!

By "logs" I am referring to the logs generated by my services. These logs are processed by Logstash and are stored in both Elasticsearch and a designated folder inside the Logstash container.

The folder path within the Logstash container where the logs are stored is **`/var/log/syslog`**. Additionally, I have **mounted** this folder with a local host folder, **`/tmp/devices_output_logs`** , so that the logs are also accessible on my CentOS 8 host.

Below is a snippet of my logstash.conf file:

```auto
input {
    // ... (input configuration)
}

output {
    elasticsearch {
        hosts => "elasticsearch:9200"
        index => "devices-logs-%{+YYYY-MM-dd}"
    }
    file {
        path => "/var/log/syslog/devices_output_logs-%{+YYYY-MM-dd}.log"
    }
}

```

I edited a little bit also the first post related to the code of the logstash service, added the volume settings.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2023, 1:16pm UTC](https://discuss.elastic.co/t/log-retention-issue-only-10-days-of-logs-kept-need-assistance/339307/4 "2023-08-23T13:16:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
