# Logging configuration issues in Kibana 7.16

**URL:** <https://discuss.elastic.co/t/logging-configuration-issues-in-kibana-7-16/295517>\
**Category:** Kibana\
**Created:** [January 26, 2022, 10:53pm UTC](https://discuss.elastic.co/t/logging-configuration-issues-in-kibana-7-16/295517 "2022-01-26T22:53:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![quality](https://avatars.discourse-cdn.com/v4/letter/q/ee7513/32.png) [@quality](https://discuss.elastic.co/u/quality)\
**Post date:** [January 26, 2022, 10:53pm UTC](https://discuss.elastic.co/t/logging-configuration-issues-in-kibana-7-16/295517/1 "2022-01-26T22:53:05Z")

</div>

Kibana 7.16

**END GOAL:**

- All Kibana logging options can be configured from `kibana.yml`
- All Kibana logs should be visible with journalctl. (they stream to journald)

* * *

* * *

**BACKGROUND** :

- The below issues were discovered after I realized that Kibana was creating a massive log file in `/var/log/kibana/kibana.log`

- Kibana was installed through the official apt repo:  
`https://artifacts.elastic.co/packages/7.x/apt stable main`

- Kibana installed using: `apt install kibana`

- I am using the official documentation for 7.16 here: [General settings in Kibana | Kibana](https://www.elastic.co/guide/en/kibana/current/settings.html)

* * *

* * *

## **FIRST ISSUE:**

_ **Provided systemd unit file has logging config hard-coded in the service file.** _

Snippet from `/etc/systemd/system/kibana.service` that was installed with the apt package:

```auto
ExecStart=/usr/share/kibana/bin/kibana --logging.dest="/var/log/kibana/kibana.log" --pid.file="/run/kibana/kibana.pid"

```

This creates an issue when you want to set logging params with in `kibana.yml` since this is essentially overriding at the command line.

I manually removed `logging.dest=` from the unit file and my logs started streaming to journald as expected.

#### **Questions for the Forum about the first issue:**

- **Why is any logging config hard-coded in this service file?** Especially sending to a flat file for any system running systemd one would want the journal to handle logging.
- **Can I override this without having to modify the supplied unit file?** Modifying or replacing it brings up compatibility concerns or overwrites if kibana is upgraded through apt. My site has several ELK servers globally and ongoing maintenance is a concern

* * *

* * *

## **SECOND ISSUE:**

_ **Logging options are not working as documented, but legacy options are** _

Using the official documentation [General settings in Kibana | Kibana](https://www.elastic.co/guide/en/kibana/current/settings.html) the config item for setting logging level should be defined as `logging.root.level`

Contents of kibana.yml

```auto
server.publicBaseUrl: "https://kibana.mysite.example.com"
server.host: "0.0.0.0"
elasticsearch.hosts: ["http://localhost:9200"]
 
logging:
  root:
    level: "warn"

```

I've also tried in-line: `logging.root.level: "warn"` and have tried quoted and unquoted `"warn" vs warn`

This does not work. Every web request is being logged and tons of noise. One refresh of the Kibana dashboard creates many lines in the log file.

However, I found in an "old" config document for **version 6.8** [Configuring Kibana | Kibana Guide [6.8] | Elastic](https://www.elastic.co/guide/en/kibana/6.8/settings.html) that there was a config param `logging.quiet`

```auto
server.publicBaseUrl: "https://kibana.mysite.example.com"
server.host: "0.0.0.0"
elasticsearch.hosts: ["http://localhost:9200"]
 
logging.quiet: true

```

So I experimented and used this 6.8 config param on my 7.16 Kibana instance and **IT WORKED** -- Logs were no longer noisy.

I have confirmed that I'm indeed using 7.16, and not 6.x:

```auto
# /usr/share/kibana/bin/kibana --allow-root --version
7.16.3

```

#### **Questions for the Forum about the second issue:**

- What is wrong with my formatting of `logging.root.level` that's causing it to not be honored?
- Is there a reason why `logging.quiet` is honored in Kibana 7.16 even though it's not documented?

Thanks!!

---

<div class="post-metadata">

**Author:** ![bhavyarm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bhavyarm/32/22392_2.png) [@bhavyarm](https://discuss.elastic.co/u/bhavyarm)\
**Post date:** [February 3, 2022, 6:23pm UTC](https://discuss.elastic.co/t/logging-configuration-issues-in-kibana-7-16/295517/2 "2022-02-03T18:23:03Z")

</div>

@jbudz / @LeeDr can you please grab this question.

Thanks,  
Bhavya

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 10, 2022, 6:58pm UTC](https://discuss.elastic.co/t/logging-configuration-issues-in-kibana-7-16/295517/3 "2022-02-10T18:58:59Z")

</div>

I think the first issue was a bug which is fixed in 8.0.0 release in this PR [https://github.com/elastic/kibana/pull/98213](https://github.com/elastic/kibana/pull/98213)

We may need someone else to comment on the second issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2022, 6:59pm UTC](https://discuss.elastic.co/t/logging-configuration-issues-in-kibana-7-16/295517/4 "2022-03-10T18:59:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
