# Shield cluster-access.log file

**URL:** <https://discuss.elastic.co/t/shield-cluster-access-log-file/31639>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 5, 2015, 3:08pm UTC](https://discuss.elastic.co/t/shield-cluster-access-log-file/31639 "2015-10-05T15:08:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![slee](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@slee](https://discuss.elastic.co/u/slee)\
**Post date:** [October 5, 2015, 3:08pm UTC](https://discuss.elastic.co/t/shield-cluster-access-log-file/31639/1 "2015-10-05T15:08:35Z")

</div>

Hello,  
I was wondering if there was a way to automatically zip up the ${cluster.name}-access.log file that's generated when auditing is enabled for shield? Similar to how you can do so in the logging.yml file for the ${cluster.name}.log file. I tried using the logging.yml file and configuring a section for the -access.log file, but that just disabled logging entirely.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 6, 2015, 3:44am UTC](https://discuss.elastic.co/t/shield-cluster-access-log-file/31639/2 "2015-10-06T03:44:38Z")

</div>

You should be able to do that with the following, just change the names accordingly.

Locate the following section in the logging.yml file and uncomment it (remove the # from the lines):

```auto
  #file:
    #type: extrasRollingFile
    #file: ${path.logs}/elasticsearch.log.gz
    #rollingPolicy: timeBased
    #rollingPolicy.FileNamePattern: ${path.logs}/${cluster.name}%d{yyyy-MM-dd}.log.gz
    #layout:
      #type: pattern
      #conversionPattern: "%d{ISO8601}"

```

Then locate the section in the logging.yml that is right above it (see below) and comment it out (add # in front of each line):

```auto
  file:
    type: dailyRollingFile
    file: ${path.logs}/${cluster.name}.log
    datePattern: "'.'yyyy-MM-dd"
    layout:
      type: pattern
      conversionPattern: "[%d{ISO8601}][%-5p][%-25c] %m%n"

```

Restart the node. Then as it rolls a new daily log file, it will compress/gz the older log file.

---

<div class="post-metadata">

**Author:** ![slee](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@slee](https://discuss.elastic.co/u/slee)\
**Post date:** [October 7, 2015, 2:01pm UTC](https://discuss.elastic.co/t/shield-cluster-access-log-file/31639/3 "2015-10-07T14:01:14Z")

</div>

ah thanks, I found the file but I wasn't sure if I was supposed to comment out the dailyRollingFile or not. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/shield-cluster-access-log-file/31639/4 "2017-07-06T13:48:18Z")

</div>


