# Unable to delete ES logs older than 7 Days with Elastic version 6.x

**URL:** <https://discuss.elastic.co/t/unable-to-delete-es-logs-older-than-7-days-with-elastic-version-6-x/159590>\
**Category:** Elasticsearch\
**Created:** [December 5, 2018, 6:46pm UTC](https://discuss.elastic.co/t/unable-to-delete-es-logs-older-than-7-days-with-elastic-version-6-x/159590 "2018-12-05T18:46:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vijayakrishna.rg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakrishna.rg/32/36798_2.png) [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Post date:** [December 5, 2018, 6:46pm UTC](https://discuss.elastic.co/t/unable-to-delete-es-logs-older-than-7-days-with-elastic-version-6-x/159590/1 "2018-12-05T18:46:39Z")

</div>

Hi,

I have configured Elasticsearch cluster with 4 nodes and i see everyday it's creating new cluster logging file in /va/log/elasticsearch

_-rw-r--r--. 1 elasticsearch elasticsearch 5323 Nov 12 17:22 myescluster-2018-11-09-1.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 310862 Nov 13 03:17 myescluster-2018-11-12-1.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 67109443 Nov 14 08:23 gc.log.0_  
_-rw-r--r--. 1 elasticsearch elasticsearch 443580 Nov 14 19:30 myescluster-2018-11-13-1.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 71803 Nov 15 00:33 myescluster-2018-11-14-1.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 67108990 Nov 15 17:29 gc.log.1_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1171038 Nov 15 18:01 myescluster-2018-11-15-1.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1122541 Nov 15 19:41 myescluster-2018-11-15-2.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 705541 Nov 16 00:00 myescluster-2018-11-15-3.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1144169 Nov 16 00:46 myescluster-2018-11-16-1.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1086573 Nov 16 17:16 myescluster-2018-11-16-2.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1081494 Nov 16 18:39 myescluster-2018-11-16-3.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1069709 Nov 16 18:48 myescluster-2018-11-16-4.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1118036 Nov 16 23:01 myescluster-2018-11-16-5.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 67109012 Nov 17 01:40 gc.log.2_  
_-rw-r--r--. 1 elasticsearch elasticsearch 67109484 Nov 18 16:46 gc.log.3_  
_-rw-r--r--. 1 elasticsearch elasticsearch 448297 Nov 19 19:52 myescluster-2018-11-16-6.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 11735 Nov 20 00:46 myescluster-2018-11-19-1.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1074127 Nov 20 09:56 myescluster-2018-11-20-1.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1075036 Nov 20 09:59 myescluster-2018-11-20-2.log.gz_  
_-rw-r--r--. 1 elasticsearch elasticsearch 1100643 Nov 20 10:13 myescluster-2018-11-20-3.log.gz_

i have updated log4j2.properties file with below information to delete es cluster logs older than 7 days.

_appender.rolling.type = RollingFile_  
_appender.rolling.name = rolling_  
_appender.rolling.fileName = {sys:es.logs.base\_path}{sys:file.separator}{sys:es.logs.cluster\_name}.log\_ \_appender.rolling.layout.type = PatternLayout\_ \_appender.rolling.layout.pattern = [%d{ISO8601}][%-5p][%-25c{1.}] %marker%.-10000m%n\_ \_appender.rolling.filePattern = {sys:es.logs.base\_path}{sys:file.separator}{sys:es.logs.cluster\_name}-%d{yy$_  
_appender.rolling.policies.type = Policies_  
_appender.rolling.policies.time.type = TimeBasedTriggeringPolicy_  
_appender.rolling.policies.time.interval = 1_  
_appender.rolling.policies.time.modulate = true_  
_appender.rolling.policies.size.type = SizeBasedTriggeringPolicy_  
_appender.rolling.policies.size.size = 128MB_  
_appender.rolling.strategy.type = DefaultRolloverStrategy_  
_appender.rolling.strategy.fileIndex = nomax_  
_appender.rolling.strategy.action.type = Delete_  
_appender.rolling.strategy.action.basepath = {sys:es.logs.base\_path}\_ \_appender.rolling.strategy.action.condition.type = IfFileName\_ \_appender.rolling.strategy.action.condition.glob = {sys:es.logs.cluster\_name}-\*_  
_#appender.rolling.strategy.action.condition.nested\_condition.type = IfAccumulatedFileSize_  
_#appender.rolling.strategy.action.condition.nested\_condition.exceeds = 2GB_

_appender.rolling.strategy.action.condition.nested\_condition.type = IfLastModified_  
\_appender.rolling.strategy.action.condition.nested\_condition.age = 7D

after updating log properties file i have restarted elastiserch service on cluster, still i see old logs in the /var/log/elasticsearch, when these logs will be deleted and is there any other setting do i need to do for it.

I want to delete both logs older than 7 days.

1. myescluster-yyyy-mm-dd-1.log.gz
2. gc.log.x

---

<div class="post-metadata">

**Author:** ![vijayakrishna.rg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vijayakrishna.rg/32/36798_2.png) [@vijayakrishna.rg](https://discuss.elastic.co/u/vijayakrishna.rg)\
**Post date:** [December 18, 2018, 7:56pm UTC](https://discuss.elastic.co/t/unable-to-delete-es-logs-older-than-7-days-with-elastic-version-6-x/159590/2 "2018-12-18T19:56:08Z")

</div>

it works for me above configuration after restarting elasticsearch service

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2019, 7:56pm UTC](https://discuss.elastic.co/t/unable-to-delete-es-logs-older-than-7-days-with-elastic-version-6-x/159590/3 "2019-01-15T19:56:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
