# Logstash log4j2.properties configuration for logs rotation

**URL:** <https://discuss.elastic.co/t/logstash-log4j2-properties-configuration-for-logs-rotation/278616>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [July 14, 2021, 7:02am UTC](https://discuss.elastic.co/t/logstash-log4j2-properties-configuration-for-logs-rotation/278616 "2021-07-14T07:02:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kshema](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kshema](https://discuss.elastic.co/u/Kshema)\
**Post date:** [July 14, 2021, 7:02am UTC](https://discuss.elastic.co/t/logstash-log4j2-properties-configuration-for-logs-rotation/278616/1 "2021-07-14T07:02:07Z")

</div>

In our application, Logstash plain log file -` logstas-plain.log` is getting converted to a zip file `logstash-plain-<date>.log.gz` each day. The zip files are getting piled up and causing a memory issue.

Any help on configuring log4j2.properties to setup the logs rotation so that older zip files can get deleted either with SizeBasedTriggeringPolicy or TimeBasedTriggeringPolicy would be appreciable.

Thanks.

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [July 14, 2021, 4:03pm UTC](https://discuss.elastic.co/t/logstash-log4j2-properties-configuration-for-logs-rotation/278616/2 "2021-07-14T16:03:41Z")

</div>

In the log4j2.properties file you need to edit these settings:

```auto
appender.rolling.policies.size.type = SizeBasedTriggeringPolicy
appender.rolling.policies.size.size = 100MB
appender.rolling.strategy.type = DefaultRolloverStrategy
appender.rolling.strategy.max = 30

```

This means that the files will rollover at 100MB and 30 files will be kept.

Change those numbers to reflect what would work best for your environment and then restart logstash.

---

<div class="post-metadata">

**Author:** ![Kshema](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kshema](https://discuss.elastic.co/u/Kshema)\
**Post date:** [July 16, 2021, 2:02pm UTC](https://discuss.elastic.co/t/logstash-log4j2-properties-configuration-for-logs-rotation/278616/3 "2021-07-16T14:02:05Z")

</div>

Thank you, @AquaX.

The default max configuration was by default set to 30 in log4j2.properties but I can see around 50 logs in our logs path as the time based roll over approach is preceding over size based approach ( log file size not reaching 100MB before 1 day finishes).

```auto
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.rolling.policies.time.interval =1
appender.rolling.strategy.max = 30

```

I have reduced values for size for testing and seems like max file number works for size based roll over. Below are the configurations:

```auto
appender.rolling.policies.size.type = SizeBasedTriggeringPolicy
appender.rolling.policies.size.size = 5KB
appender.rolling.strategy.max = 2

```

Can you please suggest on how `appender.rolling.strategy.max` value can be used for _TimeBasedTriggeringPolicy_ as well.

If that's not a possible case, is there any other way to configure the deletion of old logs for **time based roll over** approach.

Thanks again

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [July 16, 2021, 2:37pm UTC](https://discuss.elastic.co/t/logstash-log4j2-properties-configuration-for-logs-rotation/278616/4 "2021-07-16T14:37:54Z")

</div>

The `appender.rolling.strategy.max` applies to both the `TimeBasedTriggeringPolicy` and to the `SizeBasedTriggeringPolicy` since they are both using the `DefaultRolloverStrategy`.

If there were 50 logs in your log path were those all of the same log type? The `appender.rolling.strategy.max` is the maximum for each log and not the maximum for the entire log folder.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2021, 2:38pm UTC](https://discuss.elastic.co/t/logstash-log4j2-properties-configuration-for-logs-rotation/278616/5 "2021-08-13T14:38:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
