# Preventing the Logstash Log File from Filling Up Disk

**URL:** <https://discuss.elastic.co/t/preventing-the-logstash-log-file-from-filling-up-disk/47504>\
**Category:** Logstash\
**Created:** [April 15, 2016, 1:57pm UTC](https://discuss.elastic.co/t/preventing-the-logstash-log-file-from-filling-up-disk/47504 "2016-04-15T13:57:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael1/32/29279_2.png) [@Michael1](https://discuss.elastic.co/u/Michael1)\
**Post date:** [April 15, 2016, 1:57pm UTC](https://discuss.elastic.co/t/preventing-the-logstash-log-file-from-filling-up-disk/47504/1 "2016-04-15T13:57:19Z")

</div>

Hello All,

Recently I had an issue on one of my ELK nodes where it would not start for some reason. The issue was investigated further and it turns out that the Logstash log file was eating up all of the disk space for the host. We had to delete this log file to free up space, then the node was able to be brought back to life.

How do you keep this from happening? Is there documentation on this as well?

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 15, 2016, 2:03pm UTC](https://discuss.elastic.co/t/preventing-the-logstash-log-file-from-filling-up-disk/47504/2 "2016-04-15T14:03:44Z")

</div>

With the default configuration Logstash hardly logs anything so the first step would be to reduce the logging. You might also want to make sure you have log rotation in place. I think the Logstash Debian/RPM packages contain configuration for that.

---

<div class="post-metadata">

**Author:** ![Michael1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael1/32/29279_2.png) [@Michael1](https://discuss.elastic.co/u/Michael1)\
**Post date:** [April 15, 2016, 2:08pm UTC](https://discuss.elastic.co/t/preventing-the-logstash-log-file-from-filling-up-disk/47504/3 "2016-04-15T14:08:10Z")

</div>

Could you please elaborate on "reduce the logging". I stated that is what I was trying to do.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 16, 2016, 8:23pm UTC](https://discuss.elastic.co/t/preventing-the-logstash-log-file-from-filling-up-disk/47504/4 "2016-04-16T20:23:34Z")

</div>

Why was it filling up? There must have been an error causing it. Stopping that error would be the best way.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 17, 2016, 9:25am UTC](https://discuss.elastic.co/t/preventing-the-logstash-log-file-from-filling-up-disk/47504/5 "2016-04-17T09:25:12Z")

</div>

> Could you please elaborate on "reduce the logging". I stated that is what I was trying to do.

Since Logstash barely logs anything by default, there are basically two reasons why you might have large logs:

- You have enabled extra verbose logs with `--verbose` or `--debug`, or
- you have tons of errors on your logs.

So, check the level of logging and make sure you're not logging tons of errors. Also, make sure you don't have a stdout output in your configuration that's writing all events passing through Logstash to the log directory.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/preventing-the-logstash-log-file-from-filling-up-disk/47504/6 "2017-07-06T05:01:54Z")

</div>


