# Log4j2 Rolling File Strategy Only Rolls Once

**URL:** <https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320>\
**Category:** Logstash\
**Created:** [October 18, 2023, 7:37pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320 "2023-10-18T19:37:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kris\_Felscher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_felscher/32/125461_2.png) [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Post date:** [October 18, 2023, 7:37pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320/1 "2023-10-18T19:37:23Z")

</div>

I'm having issues with the log4j2 rolling file appender. It only writes the first rollover file.

Here's my config:

```auto
status = error
name = LogstashPropertiesConfig

appender.console.type = Console
appender.console.name = plain_console
appender.console.layout.type = PatternLayout
appender.console.layout.pattern = [%d{ISO8601}][%-5p][%-25c]%notEmpty{[%X{pipeline.id}]}%notEmpty{[%X{plugin.id}]} %m%n

appender.rolling.type = RollingFile
appender.rolling.name = plain_rolling
appender.rolling.fileName = ${sys:ls.logs}/logstash-current.log
appender.rolling.filePattern = ${sys:ls.logs}/{yyyy-MM-dd}-%i.log
appender.rolling.layout.type = PatternLayout
appender.rolling.layout.pattern = [%d{ISO8601}][%-5p][%-25c]%notEmpty{[%X{pipeline.id}]}%notEmpty{[%X{plugin.id}]} %m%n
appender.rolling.avoid_pipelined_filter.type = PipelineRoutingFilter
appender.rolling.policies.type = Policies
appender.rolling.policies.size.type = SizeBasedTriggeringPolicy
appender.rolling.policies.size.size = 10MB
appender.rolling.strategy.type = DefaultRolloverStrategy
appender.rolling.strategy.fileIndex = nomax

rootLogger.level = ${sys:ls.log.level}
rootLogger.appenderRef.console.ref = ${sys:ls.log.format}_console
rootLogger.appenderRef.rolling.ref = ${sys:ls.log.format}_rolling

```

I would expect this config to roll over every 10MB, creating the files:

- 2023-10-18-1.log
- 2023-10-18-2.log
- 2023-10-18-3.log
- ...etc
- logstash-current.log

where `logstash-current.log` is the log currently being written to, and the others being older data at 10MB each.

Instead, what I'm seeing is this:

- 2023-10-18-1.log
- logstash-current.log

The `2023-10-18-1.log` file is indeed 10MB, but instead of creating `2023-10-18-2.log`, log4j2 just deletes and reuses `logstash-current.log` (which never grows over 10MB).

Any thoughts?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 18, 2023, 8:16pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320/2 "2023-10-18T20:16:05Z")

</div>

[This](https://discuss.elastic.co/t/rotate-and-remove-old-logstash-output-logs/256803) thread might (or might not be helpful). Read all the way to the end 🙂

---

<div class="post-metadata">

**Author:** ![Kris\_Felscher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_felscher/32/125461_2.png) [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Post date:** [October 31, 2023, 5:54pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320/3 "2023-10-31T17:54:34Z")

</div>

Thank you, but no, that's not helpful. My problem is that the rolling appender only rolls once then continues to overwrite the "current" log file instead of creating a second log file.

---

<div class="post-metadata">

**Author:** ![Kris\_Felscher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_felscher/32/125461_2.png) [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Post date:** [October 31, 2023, 6:56pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320/4 "2023-10-31T18:56:34Z")

</div>

Update:

So it turns out that it is actually rolling files over. It's just not doing it as expected.

Right now I have 4 files:

- 2023-10-31-1.log (created 14:27)
- 2023-10-31-2.log (created 14:35)
- 2023-10-31-3.log (created 14:47)
- logstash-current.log

The problem is that log4j2 seems to be schizophrenic on when it decides to create the next file.

- 2023-10-31-1.log contains data from 14:25 to 14:27
- 2023-10-31-2.log contains data from 14:35 to 14:38
- 2023-10-31-3.log contains data from 14:47 to 14:50

So there's an 8-10 minute gap between rollovers where the logstash-current.log file just keeps getting recycled.

This makes absolutely no sense...

---

<div class="post-metadata">

**Author:** ![Kris\_Felscher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_felscher/32/125461_2.png) [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Post date:** [November 1, 2023, 1:48pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320/5 "2023-11-01T13:48:40Z")

</div>

OK, I figured it out.

We're storing our logs on an Azure Storage File Share which is mounted to the filesystem. Apparently, Log4j2 fails silently when it's unable to roll a file. I haven't identified the exact reason that the filesystem failure is occurring, but this is a Kubernetes/Azure issue, not Log4j2.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2023, 1:48pm UTC](https://discuss.elastic.co/t/log4j2-rolling-file-strategy-only-rolls-once/345320/6 "2023-11-29T13:48:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
