# Logging not happening on elastic Kubernetes Environment

**URL:** <https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [November 13, 2021, 1:01am UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107 "2021-11-13T01:01:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prabakar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabakar/32/81795_2.png) [@Prabakar](https://discuss.elastic.co/u/Prabakar)\
**Post date:** [November 13, 2021, 1:01am UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/1 "2021-11-13T01:01:06Z")

</div>

We are using Elastic on Kubernetes (ECK) Enterprise edition, we could not able to see the index creation, search request logs. In general logs will get generated inside /logs/logfile. But log files are not available for ECK environment. We tried to use below properties as well for slow logs. But logging still not happening. Please let us know how to see the logs for all our search, create, update requests. We need log to debug any issues.

PUT //\_settings  
{  
"index.search.slowlog.threshold.query.warn": "1ms",  
"index.search.slowlog.threshold.query.info": "1ms",  
"index.search.slowlog.threshold.query.debug": "1ms",  
"index.search.slowlog.threshold.query.trace": "1ms",  
"index.search.slowlog.threshold.fetch.warn": "1ms",  
"index.search.slowlog.threshold.fetch.info": "1ms",  
"index.search.slowlog.threshold.fetch.debug": "1ms",  
"index.search.slowlog.threshold.fetch.trace": "1ms"  
}

---

<div class="post-metadata">

**Author:** ![x00m](https://avatars.discourse-cdn.com/v4/letter/x/90db22/32.png) [@x00m](https://discuss.elastic.co/u/x00m)\
**Post date:** [November 14, 2021, 6:26pm UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/2 "2021-11-14T18:26:12Z")

</div>

+1  
I need this as well. I am unable to find any logs of the http requests made to Elasticsearch.

@ECK Team, please help!

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [November 15, 2021, 11:56am UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/3 "2021-11-15T11:56:27Z")

</div>

Have you tried `kubectl logs <es pod name> -n <namespace>`?

---

<div class="post-metadata">

**Author:** ![x00m](https://avatars.discourse-cdn.com/v4/letter/x/90db22/32.png) [@x00m](https://discuss.elastic.co/u/x00m)\
**Post date:** [November 15, 2021, 12:58pm UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/4 "2021-11-15T12:58:51Z")

</div>

Yes, i even set the logging level to trace. but i am not getting any logs of all the http calls made to Elasticsearch. I can only see logs of incorrect credentials, etc but not of creation of indexes, search calls, etc

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [November 15, 2021, 1:31pm UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/5 "2021-11-15T13:31:01Z")

</div>

> We are using Elastic on Kubernetes (ECK) Enterprise edition, we could not able to see the index creation, search request logs.

By default Elastisearch doesn't log all requests and this is not specific to ECK.

You can use the [Slow logs](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules-slowlog.html) to log **all** search and indexing requests by setting the thresholds to **`0s`** :

```auto
/_all/_settings -XPUT -d '{
	"index.search.slowlog.level": "trace",
	"index.search.slowlog.threshold.query.trace": "0s",
	"index.indexing.slowlog.level": "trace",
	"index.indexing.slowlog.threshold.index.trace": "0s"
}'

```

If you want all incoming HTTP requests, the HTTP layer has a tracer logger which can be dynamically activated:

```auto
/_cluster/settings -XPUT -d '{
    "transient": {
        "logger.org.elasticsearch.http.HttpTracer": "TRACE"
    }
}'

```

---

<div class="post-metadata">

**Author:** ![Prabakar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabakar/32/81795_2.png) [@Prabakar](https://discuss.elastic.co/u/Prabakar)\
**Post date:** [November 15, 2021, 11:56pm UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/6 "2021-11-15T23:56:47Z")

</div>

Still I could not able to see the request and response json on logs. I tried by updating below property to debug. But no luck.

"index.search.slowlog.level": "debug",  
"index.indexing.slowlog.level": "debug",

---

<div class="post-metadata">

**Author:** ![x00m](https://avatars.discourse-cdn.com/v4/letter/x/90db22/32.png) [@x00m](https://discuss.elastic.co/u/x00m)\
**Post date:** [November 16, 2021, 3:09pm UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/7 "2021-11-16T15:09:28Z")

</div>

Thank you. Is there a way I can specify it in the ECK yaml file under the "config:" section which is under the nodeSets ? What are those setting names?

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [November 16, 2021, 7:34pm UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/8 "2021-11-16T19:34:48Z")

</div>

The HttpTracer logger can be configured in the Elasticsearch configuration as described [here](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/logging.html#configuring-logging-levels). Example for ECK:

```auto
apiVersion: elasticsearch.k8s.elastic.co/v1
kind: Elasticsearch
metadata:
  name: foo
spec:
  version: 7.15.2
  nodeSets:
  - name: master
    count: 1
    config:
      node.store.allow_mmap: false
      logger.org.elasticsearch.http.HttpTracer: TRACE

```

The Slow logs settings are dynamic and are set per-index, which means you cannot set them in the Elasticsearch configuration and should use the update index settings API instead.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2021, 7:35pm UTC](https://discuss.elastic.co/t/logging-not-happening-on-elastic-kubernetes-environment/289107/9 "2021-12-14T19:35:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
