# Separate logging file for pluging

**URL:** <https://discuss.elastic.co/t/separate-logging-file-for-pluging/104216>\
**Category:** Elasticsearch\
**Created:** [October 17, 2017, 9:30am UTC](https://discuss.elastic.co/t/separate-logging-file-for-pluging/104216 "2017-10-17T09:30:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ov7a](https://avatars.discourse-cdn.com/v4/letter/o/ecae2f/32.png) [@ov7a](https://discuss.elastic.co/u/ov7a)\
**Post date:** [October 17, 2017, 9:30am UTC](https://discuss.elastic.co/t/separate-logging-file-for-pluging/104216/1 "2017-10-17T09:30:36Z")

</div>

According to [similar topic](https://discuss.elastic.co/t/configure-logging-for-plugin/68021):

> you cannot have more than one log4j config file.  
> [...]  
> otherwise you'd need a dedicated log file per plugin.

However, according to [docs](https://www.elastic.co/guide/en/x-pack/5.6/auditing.html), X-Pack plugin has exactly that:

> You configure also configure how the logfile is written in the `log4j2.properties` file located in `CONFIG_DIR/x-pack`

(Btw, there is a typo: "configure" instead of "can" )

So, X-Pack does have a separate logging file for its audit log.

1. How does it loaded?
2. Is there a way to configure my plugin to have a separate log? I've tried to create a `log4j2.properties` in `CONFIG_DIR/<plugin-name>` but that did not work.

**Update**  
Digging into [docs](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/settings.html) i found that:

> Multiple configuration files can be loaded (in which case they will get merged) as long as they are named `log4j2.properties` and have the Elasticsearch config directory as an ancestor; this is useful for plugins that expose additional loggers. The logger section contains the java packages and their corresponding log level. The appender section contains the destinations for the logs. Extensive information on how to customize logging and all the supported appenders can be found on the Log4j documentation.

Maybe there is some problem with my installation then.  
The root of my configuration is `/etc/elasticsearch`  
I have two instances of it, so their configurations stored in `/etc/elasticsearch/instance1` and `/etc/elasticsearch/instance2`. If I place a `log4j2.properties` file to any subfolder of instance folder, it works fine. But x-pack plugin config is installed to `/etc/elasticsearch/x-pack`, so `/etc/elasticsearch/x-pack/log4j2.properties` is not being loaded. How can I properly fix this?

For now, I've just created two symlinks.  
Probably related issue: [Plugins, instances and configs · Issue #226 · voxpupuli/puppet-elasticsearch · GitHub](https://github.com/elastic/puppet-elasticsearch/issues/226)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2017, 9:30am UTC](https://discuss.elastic.co/t/separate-logging-file-for-pluging/104216/2 "2017-11-14T09:30:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
