# Question on what Elasticsearch considers data vs logs

**URL:** https://discuss.elastic.co/t/question-on-what-elasticsearch-considers-data-vs-logs/263506
**Category:** Elasticsearch
**Created:** [February 6, 2021, 5:24pm UTC](https://discuss.elastic.co/t/question-on-what-elasticsearch-considers-data-vs-logs/263506 "2021-02-06T17:24:18Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![halfbakedprod](https://avatars.discourse-cdn.com/v4/letter/h/cdc98d/32.png) [@halfbakedprod](https://discuss.elastic.co/u/halfbakedprod)
#### Post date: [February 6, 2021, 5:24pm UTC](https://discuss.elastic.co/t/question-on-what-elasticsearch-considers-data-vs-logs/263506/1 "2021-02-06T17:24:18Z")

</div>

Hello all,

I just setup Graylog + Elasticsearch for my first time. I'm trying to change the default location that ingested logs are saved. Currently, the default filepath is the OS drive, which will fill up in no time.

Looking at the documentation, I see that there are two filepaths to change in the config file, one for data and one for logs. However, I'm confused by the two. Are logs (/var/logs/elasticsearch) Elasticsearch's own logs, or ingested logs? Or are ingested logs considered data?

In addition to changing the filepath in the .yml file, is there anything else I need to do to make this all work? Anything in Graylog, etc?

Thanks for your time.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [February 6, 2021, 6:10pm UTC](https://discuss.elastic.co/t/question-on-what-elasticsearch-considers-data-vs-logs/263506/2 "2021-02-06T18:10:12Z")

</div>

Hi @halfbakedprod Welcome to the community and thanks for trying Elasticsearch

1st I love your username 🙂

BTW Great questions here is the [quick docs on that](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/important-settings.html#path-settings)

Logs that are ingested into Elasticsearch end up in Indices in Elasticsearch that data is stored in `path.data` example `/var/data/elasticsearch`

The Logs that Elasticsearch generates in the course of operating are stored in `path.logs` example `/var/log/elasticsearch`

You can set those 2 paths to whichever paths make sense for your deployment.

And of course to complete the equation if you want to ingest the logs generated by elasticsearch back into elasticsearch you would use Filebeat and set the path to harvest the elasticsearch logs from where you pointed the elasticsearch logs to ... i.e. `path.logs`. We actually have [a filebeat module for that.](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-elasticsearch.html)

Typically if you are looking to ingest logs you would use [Filebeat](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html) or perhaps our [new Fleet with the new Elastic Agent which is in Beta](https://www.elastic.co/guide/en/fleet/current/fleet-quick-start.html)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 6, 2021, 6:10pm UTC](https://discuss.elastic.co/t/question-on-what-elasticsearch-considers-data-vs-logs/263506/3 "2021-03-06T18:10:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
