# Logs in Logstash / archive

**URL:** <https://discuss.elastic.co/t/logs-in-logstash-archive/205640>\
**Category:** Logs\
**Created:** [October 29, 2019, 10:29am UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640 "2019-10-29T10:29:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![juuuhuuu](https://avatars.discourse-cdn.com/v4/letter/j/958977/32.png) [@juuuhuuu](https://discuss.elastic.co/u/juuuhuuu)\
**Post date:** [October 29, 2019, 10:29am UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640/1 "2019-10-29T10:29:39Z")

</div>

Hello,  
Im new in elastic.  
I would like to know, for how long the logs are "active " in logstash. Can I archive them, if yes how?

Thank you

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 29, 2019, 11:04am UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640/2 "2019-10-29T11:04:20Z")

</div>

Hi @juuuhuuu,

glad you're giving the Elastic Stack a try. I can't quite follow your question, though. Logstash is a piece of our stack that can perform the transformation of data before it is ingested into Elasticsearch. Could you elaborate on what you mean by "active"?

---

<div class="post-metadata">

**Author:** ![juuuhuuu](https://avatars.discourse-cdn.com/v4/letter/j/958977/32.png) [@juuuhuuu](https://discuss.elastic.co/u/juuuhuuu)\
**Post date:** [October 30, 2019, 11:47am UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640/3 "2019-10-30T11:47:49Z")

</div>

Hello @weltenwort,

Thank you for your answer. I would like to use ELK Stack to send just error Logs in Logstash-\> Elasticsearch -\> Kibana. Is it possible to archive the error Logs ? If yes, how?.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 30, 2019, 12:07pm UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640/4 "2019-10-30T12:07:39Z")

</div>

I see, so you're asking about how to manage the retention of the log messages?

With the log messages being stored in Elasticsearch, this is the place were any retention policy would be configured. Elasticsearch supports quite elaborate automatic [index life cycle management](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html). What the specific recommended index layout and life cycle policy is depends on you definition of "active" and "archived". Should archived log entries be deleted? Should they be searchable but located on nodes with cheaper storage? It really depends on your scenario and requirements.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [October 30, 2019, 12:09pm UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640/5 "2019-10-30T12:09:44Z")

</div>

There's a [blog post about index lifecycle management (ILM)](https://www.elastic.co/blog/implementing-hot-warm-cold-in-elasticsearch-with-index-lifecycle-management) on our blog that walks through an example scenario. I highly recommend giving that a read.

---

<div class="post-metadata">

**Author:** ![juuuhuuu](https://avatars.discourse-cdn.com/v4/letter/j/958977/32.png) [@juuuhuuu](https://discuss.elastic.co/u/juuuhuuu)\
**Post date:** [October 30, 2019, 12:24pm UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640/6 "2019-10-30T12:24:00Z")

</div>

Thank You very much. Great, I was searching for something like that .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2019, 12:24pm UTC](https://discuss.elastic.co/t/logs-in-logstash-archive/205640/7 "2019-11-27T12:24:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
