# Logstash logging options (rotating, removing old logs, etc)

**URL:** <https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966>\
**Category:** Logstash\
**Created:** [September 9, 2015, 8:43pm UTC](https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966 "2015-09-09T20:43:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![edouglass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edouglass/32/4670_2.png) [@edouglass](https://discuss.elastic.co/u/edouglass)\
**Post date:** [September 9, 2015, 8:43pm UTC](https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966/1 "2015-09-09T20:43:15Z")

</div>

Hello! Thanks for any help!  
When running logstash, I am aware of the --log option that allows you to specify a log directory for logstash to log to. However, I do not know what logstash's settings are for rotating log files, removing old logs, etc. Currently, it seems as if logstash is leaving behind zipped logs for all history. Are there settings that I can use to automatically remove old logs? Or is the best way to do this using a cron job or something? I hope this question isn't too redundant, I had a hard time finding google results surrounding the logging behavior of logstash itself.

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 9, 2015, 9:21pm UTC](https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966/2 "2015-09-09T21:21:05Z")

</div>

Logstash installs a logrotate configuration file to /etc/logrotate.d. By default the file will be rotated daily and kept around for seven days.

---

<div class="post-metadata">

**Author:** ![edouglass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edouglass/32/4670_2.png) [@edouglass](https://discuss.elastic.co/u/edouglass)\
**Post date:** [September 9, 2015, 11:27pm UTC](https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966/3 "2015-09-09T23:27:25Z")

</div>

Okay great! Thanks for the response. I see the config file like you said. Is there logstash documentation on what it decides to put in this file?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 10, 2015, 3:36am UTC](https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966/4 "2015-09-10T03:36:59Z")

</div>

Not sure what you mean. Some kind of rationale behind the decision to rotate each day and keep the logs for seven days? No, there's no such documentation. Those number were probably chosen rather arbitrarily since they were nice and round and seemed like reasonably good ballpark figures.

---

<div class="post-metadata">

**Author:** ![edouglass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/edouglass/32/4670_2.png) [@edouglass](https://discuss.elastic.co/u/edouglass)\
**Post date:** [September 10, 2015, 5:51pm UTC](https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966/5 "2015-09-10T17:51:39Z")

</div>

I meant is there a website or some document published by elastic that I could have read that would have given me the information that you gave me in your first reply? Where can I read about the fact that logstash installs a lograte config in /etc/logrotate.d?  
Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 10, 2015, 6:48pm UTC](https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966/6 "2015-09-10T18:48:39Z")

</div>

That's not documented.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:29am UTC](https://discuss.elastic.co/t/logstash-logging-options-rotating-removing-old-logs-etc/28966/7 "2017-07-06T05:29:28Z")

</div>


