# Understanding the default behaviour of log rotation of file output plugin

**URL:** <https://discuss.elastic.co/t/understanding-the-default-behaviour-of-log-rotation-of-file-output-plugin/189339>\
**Category:** Logstash\
**Created:** [July 8, 2019, 12:00pm UTC](https://discuss.elastic.co/t/understanding-the-default-behaviour-of-log-rotation-of-file-output-plugin/189339 "2019-07-08T12:00:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Satish\_Mundru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/satish_mundru/32/46276_2.png) [@Satish\_Mundru](https://discuss.elastic.co/u/Satish_Mundru)\
**Post date:** [July 8, 2019, 12:00pm UTC](https://discuss.elastic.co/t/understanding-the-default-behaviour-of-log-rotation-of-file-output-plugin/189339/1 "2019-07-08T12:00:23Z")

</div>

Hi,  
As I understood that the log is rotated per day by using this config 'path' parameter -  
file {  
path =\> "/var/logstash/server-%{+YYYY-MM-dd}.log"  
codec =\> line { format =\> "%{[message]}"}  
}

A) I'm trying to make it a generic in Logstash configuration to pass the filename as event from filebeat, say filename: server-%{+YYYY-MM-DD}.log

when I apply this filename in logstash config as below  
file {  
path =\> "/var/logstash/%{filename}"  
codec =\> line { format =\> "%{[message]}"}  
}

file is generated with name server-%{YYYY-MM-DD}.log instead of server-2019-07-08.log.

b) What would be the default behaviour if I give path =\> "/var/logstash/server.log in config, as noticed it always append the logs. Does it honour the file size. please provide inputs

C) Saw this link to get some details - [Logstash Output File Rotate](https://discuss.elastic.co/t/logstash-output-file-rotate/76782), would not solve my use case.

Please suggest the approach.

Thanks,  
Satish

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 8, 2019, 11:57pm UTC](https://discuss.elastic.co/t/understanding-the-default-behaviour-of-log-rotation-of-file-output-plugin/189339/2 "2019-07-08T23:57:39Z")

</div>

This looks more related to Logstash. Filebeat sends the absolute file path to logstash. You would have to use grok or the ruby filter to find the actual base name (plus/minus dates). Yet I don't know if the file output support a format string to the path setting.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2019, 12:45am UTC](https://discuss.elastic.co/t/understanding-the-default-behaviour-of-log-rotation-of-file-output-plugin/189339/3 "2019-07-09T00:45:25Z")

</div>

Yeah, the file output will do a sprintf on the path option.

```
output { file { path => "/tmp/server-%{+YYYY-MM-dd}.log" } }

```

will result in

```
Opening file {:path=>"/tmp/server-2019-07-09.log"}

```

but that pre-supposes that the [@timestamp] field has been parsed correctly out of something in the original message.

---

<div class="post-metadata">

**Author:** ![Satish\_Mundru](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/satish_mundru/32/46276_2.png) [@Satish\_Mundru](https://discuss.elastic.co/u/Satish_Mundru)\
**Post date:** [July 9, 2019, 4:00am UTC](https://discuss.elastic.co/t/understanding-the-default-behaviour-of-log-rotation-of-file-output-plugin/189339/4 "2019-07-09T04:00:02Z")

</div>

Thanks Steffens.

i'm new to writing the filters, however will try.  
The use cases targeting is filebeat harvesting 5 files and sent to single Logstash, we want to store the corresponding 5 files in logstash centralised location mention in generic path location.

Can anyone help in this regard.

Thanks,  
Satish

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2019, 4:00am UTC](https://discuss.elastic.co/t/understanding-the-default-behaviour-of-log-rotation-of-file-output-plugin/189339/5 "2019-08-06T04:00:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
