# No Logs in Log Folder

**URL:** <https://discuss.elastic.co/t/no-logs-in-log-folder/99442>\
**Category:** Elasticsearch\
**Created:** [September 5, 2017, 2:04pm UTC](https://discuss.elastic.co/t/no-logs-in-log-folder/99442 "2017-09-05T14:04:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![uber1923](https://avatars.discourse-cdn.com/v4/letter/u/57b2e6/32.png) [@uber1923](https://discuss.elastic.co/u/uber1923)\
**Post date:** [September 5, 2017, 2:04pm UTC](https://discuss.elastic.co/t/no-logs-in-log-folder/99442/1 "2017-09-05T14:04:33Z")

</div>

Hi All,

I am using the docker image for elasticsearch 5.5.2 and so far I have been able to set it up fine. Now I want to take a copy of the logs and do something with them. I mount a folder to the docker run command so that the log files are available to me outside of the container.

I have set "xpack.security.audit.enabled: true" and also added path.logs in the elasticsearch.yml file. (path.logs: "/usr/share/elasticsearch/logs") which is mounted to a external folder. (- -volume ~/documents/elasticsearch/logs:/usr/share/elasticsearch/logs). Also made sure that the elasticsearch user has permissions to the data and log folder (owned by root and chmod to 777 as it is only in dev).

When I go to the log folder on the host machine, it is empty also when I exec into the docker container and cd to /usr/share/elasticsearch/logs that is empty as well.

I have read the online documentation and I think I have covered everything. It also seems from the documentation that the logs should be saved automatically after changing the xpack.security.audit.enabled  
Have I missed a setting with needs to be changed in order for the logs to be saved?

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [September 9, 2017, 11:13pm UTC](https://discuss.elastic.co/t/no-logs-in-log-folder/99442/2 "2017-09-09T23:13:17Z")

</div>

Logs should have been written even without those settings defined. Can you post here your Dockerfile? Also, what's the output of `docker logs`?

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [September 10, 2017, 1:02am UTC](https://discuss.elastic.co/t/no-logs-in-log-folder/99442/3 "2017-09-10T01:02:06Z")

</div>

I assume that you're referring to the official Elastic images.

By default, the Elasticsearch and audit logs go to stdout: [https://github.com/elastic/elasticsearch-docker/blob/5.5/build/elasticsearch/x-pack/log4j2.properties](https://github.com/elastic/elasticsearch-docker/blob/5.5/build/elasticsearch/x-pack/log4j2.properties)

You have to collect these logs via that, or override this behavior if you want something different.

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [September 10, 2017, 1:22am UTC](https://discuss.elastic.co/t/no-logs-in-log-folder/99442/4 "2017-09-10T01:22:57Z")

</div>

Forget what I said. I was not aware that our Docker images would send only to stdout. Thanks @jasontedor

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2017, 1:23am UTC](https://discuss.elastic.co/t/no-logs-in-log-folder/99442/5 "2017-10-08T01:23:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
