# Logrotate

**URL:** <https://discuss.elastic.co/t/logrotate/173643>\
**Category:** Logstash\
**Created:** [March 24, 2019, 2:40pm UTC](https://discuss.elastic.co/t/logrotate/173643 "2019-03-24T14:40:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![praveen1](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@praveen1](https://discuss.elastic.co/u/praveen1)\
**Post date:** [March 24, 2019, 2:40pm UTC](https://discuss.elastic.co/t/logrotate/173643/1 "2019-03-24T14:40:02Z")

</div>

Hi Teams,  
can anyone help me in configuring logrotate in "version" : {"number" : "6.1.1", to reduce my Disk size,  
I want to only keep 7 days logs and in zipped format.  
i could see these 2 file in logstash file: log4j2.properties logstash.yml

Thanks

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [March 24, 2019, 9:59pm UTC](https://discuss.elastic.co/t/logrotate/173643/2 "2019-03-24T21:59:38Z")

</div>

Heya, welcome to the community. Can you clarify, are you asking about Elasticsearch or Logstash?

---

<div class="post-metadata">

**Author:** ![praveen1](https://avatars.discourse-cdn.com/v4/letter/p/4491bb/32.png) [@praveen1](https://discuss.elastic.co/u/praveen1)\
**Post date:** [March 25, 2019, 5:29am UTC](https://discuss.elastic.co/t/logrotate/173643/3 "2019-03-25T05:29:57Z")

</div>

Hi jason,  
its about logstash.  
it was around 4 days back my Disk turn as critical all of sudden, after investigating i found /var/logstash/ --- taking lots of space, and it was like last month logs, so i cleaned it and kept a cron job to keep only for 7 days.But again yesterday, automatically logs size increased like hell, as of now i have zipped it, But looking fwd with Log-rotate to keep (i only want to keep 7 Days logs not more than), can you please help in this.

Thanks

---

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [March 25, 2019, 10:06am UTC](https://discuss.elastic.co/t/logrotate/173643/4 "2019-03-25T10:06:49Z")

</div>

The log4j2.properties will contain the log rotation directives - you need to understand log4j syntax to modify it however.

On our systems, we've opted for a simple crontab entry:

```
* 0 * * * /usr/bin/find /logs/logstash -type f -mtime +7 -delete
```

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [March 25, 2019, 10:40am UTC](https://discuss.elastic.co/t/logrotate/173643/5 "2019-03-25T10:40:07Z")

</div>

Since this is about Logstash, we moved this to the Logstash category.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 22, 2019, 10:40am UTC](https://discuss.elastic.co/t/logrotate/173643/6 "2019-04-22T10:40:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
