# Rotated log files have incorrect permissions

**URL:** <https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [August 11, 2020, 7:11pm UTC](https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623 "2020-08-11T19:11:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![drjan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drjan/32/67120_2.png) [@drjan](https://discuss.elastic.co/u/drjan)\
**Post date:** [August 11, 2020, 7:11pm UTC](https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623/1 "2020-08-11T19:11:54Z")

</div>

When log files are rotated by metricbeat, the files created do not have the permissions specified in the metricbeat.yml file.

Here's part of metricbeat.yml:

```auto
logging.to_files: true
logging.files:
  path: /var/log/metricbeat
  name: metricbeat.log
  keepfiles: 14
  permissions: 0666
  interval: 24h
  rotateonstartup: true

```

And here are the log files in /var/log/metricbeat after it was restarted a number of times:

```auto
-rw-r-----. 1 root root 64031 Aug 11 19:10 metricbeat.log
-rw-r--r--. 1 root root 183 Aug 11 18:44 metricbeat.log-2020-08-11-1
-rw-r--r--. 1 root root 3334 Aug 11 18:44 metricbeat.log-2020-08-11-2
-rw-r-----. 1 root root 11634 Aug 11 18:45 metricbeat.log-2020-08-11-3
-rw-r-----. 1 root root 20225 Aug 11 18:49 metricbeat.log-2020-08-11-4
-rw-r-----. 1 root root 14298 Aug 11 18:51 metricbeat.log-2020-08-11-5

```

I don't really need 666 permissions on the log files (644 would be marvellous), it was a desperate act to see if anything would affect the file perms.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 11, 2020, 10:11pm UTC](https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623/2 "2020-08-11T22:11:21Z")

</div>

This is a security measure. Any files/folders created by Beats get a umask of 0027. This means any files will have at most 0640 permissions and any folders will have at most 0750 permissions. Essentially, we deliberately don't want any Beats-created files/folders to be world-readable.

Ref: [https://github.com/elastic/beats/issues/14005](https://github.com/elastic/beats/issues/14005) and [https://github.com/elastic/beats/pull/14119](https://github.com/elastic/beats/pull/14119).

Shaunak

---

<div class="post-metadata">

**Author:** ![drjan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drjan/32/67120_2.png) [@drjan](https://discuss.elastic.co/u/drjan)\
**Post date:** [August 13, 2020, 8:32am UTC](https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623/3 "2020-08-13T08:32:23Z")

</div>

Thanks for the speedy response 🙂

Can you update the documentation please? Right now it's actively misleading.

[https://www.elastic.co/guide/en/beats/filebeat/current/configuration-logging.html#\_logging\_files\_permissions](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-logging.html#_logging_files_permissions)

Thank you 🙂

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 13, 2020, 10:40am UTC](https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623/4 "2020-08-13T10:40:01Z")

</div>

Created [https://github.com/elastic/beats/issues/20584](https://github.com/elastic/beats/issues/20584) to request and track the documentation update.

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2020, 12:40pm UTC](https://discuss.elastic.co/t/rotated-log-files-have-incorrect-permissions/244623/5 "2020-09-10T12:40:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
