# Log4j management of access files created by Elasticsearch

**URL:** <https://discuss.elastic.co/t/log4j-management-of-access-files-created-by-elasticsearch/307249>\
**Category:** Elasticsearch\
**Created:** [June 15, 2022, 10:00am UTC](https://discuss.elastic.co/t/log4j-management-of-access-files-created-by-elasticsearch/307249 "2022-06-15T10:00:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![intrepid1](https://avatars.discourse-cdn.com/v4/letter/i/dbc845/32.png) [@intrepid1](https://discuss.elastic.co/u/intrepid1)\
**Post date:** [June 15, 2022, 10:00am UTC](https://discuss.elastic.co/t/log4j-management-of-access-files-created-by-elasticsearch/307249/1 "2022-06-15T10:00:09Z")

</div>

Hi there,

I am running Elasticsearch 7.16.1 and also have auditing configured. I am using a default log4j properties files which I had to extend to gzip the audit files. This is not included in the 7.16.1 log4j2 properties file.

However I note that access logs are being generated in the form of \<cluster\_name\>\_access.log. These files are being rolled over every night but there seems to be nothing in the log4j2 properties file to manage such files. I cannot see any mention of access files in the properties file. I assume they are picked up by some other rolling.filePattern. However none seems to match. I am confused.

Does anyone else have a similar problem?

I did raise a ticket, but as Log4j is a third-party library and comes with a reasonable default configuration, they wouldn't progress it.

Kind regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2022, 10:00am UTC](https://discuss.elastic.co/t/log4j-management-of-access-files-created-by-elasticsearch/307249/2 "2022-07-13T10:00:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
