# Up to date way to ingest logs from Java application using log4j2

**URL:** <https://discuss.elastic.co/t/up-to-date-way-to-ingest-logs-from-java-application-using-log4j2/241300>\
**Category:** Logstash\
**Created:** [July 15, 2020, 1:10pm UTC](https://discuss.elastic.co/t/up-to-date-way-to-ingest-logs-from-java-application-using-log4j2/241300 "2020-07-15T13:10:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniele\_Renda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniele_renda/32/39939_2.png) [@Daniele\_Renda](https://discuss.elastic.co/u/Daniele_Renda)\
**Post date:** [July 15, 2020, 1:10pm UTC](https://discuss.elastic.co/t/up-to-date-way-to-ingest-logs-from-java-application-using-log4j2/241300/1 "2020-07-15T13:10:56Z")

</div>

Hi, I've a Spring Boot 2.3.1 application that produces some logs. I'd like to ingest them into my ElasticSearch stack (I'm hosted on Elastic cloud).  
What's the better way to do that? I saw the logstash log4j plugin is deprecated.

I saw some alternatives like [https://github.com/rfoltyns/log4j2-elasticsearch](https://github.com/rfoltyns/log4j2-elasticsearch) but I'm not sure is the recomended way. Another approach is to use LogTash: [https://medium.com/@d.lopez.j/easily-connecting-your-spring-boot-applications-to-the-elastic-stack-with-log4j2-1809e81c6a2e](https://medium.com/@d.lopez.j/easily-connecting-your-spring-boot-applications-to-the-elastic-stack-with-log4j2-1809e81c6a2e)

BTW, I'm also using APM in my server application.

Thanks

---

<div class="post-metadata">

**Author:** ![Daniele\_Renda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniele_renda/32/39939_2.png) [@Daniele\_Renda](https://discuss.elastic.co/u/Daniele_Renda)\
**Post date:** [August 6, 2020, 5:03pm UTC](https://discuss.elastic.co/t/up-to-date-way-to-ingest-logs-from-java-application-using-log4j2/241300/2 "2020-08-06T17:03:15Z")

</div>

Hey guys, any hint about this? Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 6, 2020, 6:08pm UTC](https://discuss.elastic.co/t/up-to-date-way-to-ingest-logs-from-java-application-using-log4j2/241300/3 "2020-08-06T18:08:04Z")

</div>

GELF might be an option. See [this](https://www.shortn0tes.com/2018/02/elk-stack-with-log4j.html) blog.

---

<div class="post-metadata">

**Author:** ![Daniele\_Renda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniele_renda/32/39939_2.png) [@Daniele\_Renda](https://discuss.elastic.co/u/Daniele_Renda)\
**Post date:** [August 7, 2020, 8:00am UTC](https://discuss.elastic.co/t/up-to-date-way-to-ingest-logs-from-java-application-using-log4j2/241300/4 "2020-08-07T08:00:26Z")

</div>

Thanks for the hint. I was looking something integrated in my application. In fact it's distributed automatically on AWS EC2 and the machine is a pretty standard linux machine. I should see if I can change the machine template and install the software + configuration. It's a bit tricky.

Using a Java library would be much easier.

Thanks!

---

<div class="post-metadata">

**Author:** ![rfoltyns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rfoltyns/32/29086_2.png) [@rfoltyns](https://discuss.elastic.co/u/rfoltyns)\
**Post date:** [September 2, 2020, 11:07pm UTC](https://discuss.elastic.co/t/up-to-date-way-to-ingest-logs-from-java-application-using-log4j2/241300/5 "2020-09-02T23:07:02Z")

</div>

Hi Danielle,

It's all about the trade-offs.

Logstash is a mature product that offers vast variety of plugins, log processing options, delivery strategies, Elasticsearch API integrations and - most of all - [elastic.co](http://elastic.co) support and offloading log delivery to other processes. It's just the safest bet.

Alternatives like log4j2-elasticsearch (thanks for mentioning) offer a simple bulk delivery with a few failover options and just a few API integrations: Index template, ILM policy (coming in 1.5) and - most of all - all the work is done within the same process as your business logic, which in some scenarios might put your application at risk.

But it's very easy to extend, customize and work with. Control of the output is much closer to the application/developer/business and you usually need to just refurbish current log4j2.xml configuration. Also, CPU and memory footprint is very small (especially when using log4j2-elasticsearch-hc module) even at very high workload.

If you have any trouble setting it up just raise an issue.  
If you have any features you'd like to have implemented just raise an issue.  
If you'd like to contribute, send me an email or just raise a PR.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 30, 2020, 11:07pm UTC](https://discuss.elastic.co/t/up-to-date-way-to-ingest-logs-from-java-application-using-log4j2/241300/6 "2020-09-30T23:07:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
