# Logstash when started using nohup, it is logging too much resulting in huge size

**URL:** <https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560>\
**Category:** Logstash\
**Created:** [June 21, 2021, 3:45pm UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560 "2021-06-21T15:45:23Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![mastersmit](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Post date:** [June 21, 2021, 3:45pm UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/1 "2021-06-21T15:45:24Z")

</div>

we are running logstash and its output has `file` and `elasticsearch` for every opening and closing the `file` plugin is logging in... resulting the nohup.out file being very huge...

How do i avoid so much of logging, or is there a way better way to handle this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 21, 2021, 4:29pm UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/2 "2021-06-21T16:29:52Z")

</div>

You could change the logging level for the loggers involved (the logger name is show in the log message). For example, to increase the volume of log messages from a file output I use

```
curl -XPUT 'localhost:9600/_node/logging?pretty' -H 'Content-Type: application/json' -d'
{
    "logger.filewatch.discoverer" : "TRACE",
    "logger.filewatch.observingtail" : "TRACE",
    "logger.filewatch.sincedbcollection" : "TRACE",
    "logger.filewatch.tailmode.handlers.createinitial" : "TRACE",
    "logger.filewatch.tailmode.handlers.grow" : "TRACE",
    "logger.filewatch.tailmode.processor" : "TRACE"
}
'

```

You could change the default (INFO) level to WARN in a similar way.

---

<div class="post-metadata">

**Author:** ![mastersmit](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Post date:** [June 23, 2021, 12:35pm UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/3 "2021-06-23T12:35:48Z")

</div>

Thanks. Any possibility i can set this at the properties, instead of a curl? as our logstash gets run every now and then and by different people. So aligning this everytime the logstash starts may be difficult.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 23, 2021, 4:44pm UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/4 "2021-06-23T16:44:25Z")

</div>

Yes, you should be able to modify the log4j2.properties file to set these.

---

<div class="post-metadata">

**Author:** ![mastersmit](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Post date:** [June 28, 2021, 7:44am UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/5 "2021-06-28T07:44:51Z")

</div>

I tried adding

`logger.logstash.file.outputs = WARN `

and

```auto
"logger.filewatch.discoverer" : "TRACE",
    "logger.filewatch.observingtail" : "TRACE",
    "logger.filewatch.sincedbcollection" : "TRACE",
    "logger.filewatch.tailmode.handlers.createinitial" : "TRACE",
    "logger.filewatch.tailmode.handlers.grow" : "TRACE",
    "logger.filewatch.tailmode.processor" : "TRACE"

```

But both giving me error by either saying logstash file output is not valid or filewatch module not found.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 28, 2021, 5:03pm UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/6 "2021-06-28T17:03:29Z")

</div>

To modify the level for all of the filewatch classes you could use

```
logger.filewatch.name = filewatch
logger.filewatch.level = WARN

```

If you wanted to modify some sub-classes but not others you could use something like

```
logger.logstash1.name = logstash.runner
logger.logstash1.level = WARN
logger.logstash2.name = logstash.pipeline
logger.logstash2.level = WARN

```

which does not modify logstash.javapipeline, logstash.setting, etc.

---

<div class="post-metadata">

**Author:** ![mastersmit](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Post date:** [July 1, 2021, 11:30am UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/7 "2021-07-01T11:30:41Z")

</div>

> [@Badger](#):
>
> `logger`

Thanks for the reponse.

Even after trying both I am still seeing those logs

Sample Log (the one i need to get rid of)

```auto
[2021-07-01T19:28:45,203][INFO][logstash.outputs.file][main][4e6acc3dcf51fc251f2e81c7fe7f576133e96a5af8f803fa5d198ccbec9f5a00] Opening file {:path=>"/Users/Smit/Downloads/trash/log.txt"}

```

Properties I tried:

```auto
logger.filewatch.name = filewatch
logger.filewatch.level = WARN

```

another

```auto
logger.logstash1.name = logstash.outputs.file
logger.logstash1.level = WARN

```

Sample Logstash Conf:

```auto
input {
  stdin{}
}

output {
  file {
   path => "/Users/Smit/Downloads/trash/log.txt"
   codec => line { format => "custom format: %{message}"}
 }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 1, 2021, 5:40pm UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/8 "2021-07-01T17:40:09Z")

</div>

I do not know what to say. When I add

```auto
logger.logstash1.name = logstash.outputs.file
logger.logstash1.level = WARN

```

to /etc/logstash/log4j2.properties and restart logstash the message

`[INFO][logstash.outputs.file][main][98cb9fbcc7c0b63c6dfb54eee928e0944a186fb8cd23c2f926042405b89ccd1f] Opening file {:path=>"/tmp/foo.txt"}`

is not printed.

---

<div class="post-metadata">

**Author:** ![mastersmit](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@mastersmit](https://discuss.elastic.co/u/mastersmit)\
**Post date:** [July 2, 2021, 4:50am UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/9 "2021-07-02T04:50:02Z")

</div>

Thanks.

The problem is I was updating the log4j in the config folder but i was not setting that in the --path.settings. After doing that, it worked.

`--path.settings=/Users/Smit/Documents/Dev/ELK/logstash-7.10.0/config/`

or

`export LS_SETTINGS_DIR=/Users/Smit/Documents/Dev/ELK/logstash-7.10.0/config/`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2021, 4:50am UTC](https://discuss.elastic.co/t/logstash-when-started-using-nohup-it-is-logging-too-much-resulting-in-huge-size/276560/10 "2021-07-30T04:50:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
