# Where does logstash store the log files that it has read

**URL:** <https://discuss.elastic.co/t/where-does-logstash-store-the-log-files-that-it-has-read/24695>\
**Category:** Logstash\
**Created:** [July 1, 2015, 8:51am UTC](https://discuss.elastic.co/t/where-does-logstash-store-the-log-files-that-it-has-read/24695 "2015-07-01T08:51:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![simonrisberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simonrisberg/32/3513_2.png) [@simonrisberg](https://discuss.elastic.co/u/simonrisberg)\
**Post date:** [July 1, 2015, 8:51am UTC](https://discuss.elastic.co/t/where-does-logstash-store-the-log-files-that-it-has-read/24695/1 "2015-07-01T08:51:02Z")

</div>

Hi!

I was wondering where Logstash is storing the log files that it has read and indexed. I was reading up a little on github and apparently the default folder for this is var/log/syslog but when I jump into the log folder I cannot find a file called syslog. I don't know if this is a setting that you must change somewhere. Worth mentioning is that I am not using a logstash forwarder. Right now I'm having everything on the same server just to try it out and explore.

Any help would be appreciated.

Best regards

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 1, 2015, 9:10am UTC](https://discuss.elastic.co/t/where-does-logstash-store-the-log-files-that-it-has-read/24695/2 "2015-07-01T09:10:36Z")

</div>

Logstash doesn't have any default or mandatory storage of processed logs. It does ship with several output plugins that you can use to send logs to e.g. files, databases, message brokers, or to Elasticsearch, but it's up to you to configure that according to your needs.

---

<div class="post-metadata">

**Author:** ![simonrisberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simonrisberg/32/3513_2.png) [@simonrisberg](https://discuss.elastic.co/u/simonrisberg)\
**Post date:** [July 1, 2015, 9:27am UTC](https://discuss.elastic.co/t/where-does-logstash-store-the-log-files-that-it-has-read/24695/3 "2015-07-01T09:27:16Z")

</div>

Thank you 🙂 So what I need is a plugin that ships the read log files to a single logfile that I'm pointing out I guess 🙂 Will look for this plugin 😄

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 1, 2015, 9:52am UTC](https://discuss.elastic.co/t/where-does-logstash-store-the-log-files-that-it-has-read/24695/4 "2015-07-01T09:52:28Z")

</div>

I've never seen a need for doing anything like that, but sure, just use the [file output](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-file.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/where-does-logstash-store-the-log-files-that-it-has-read/24695/5 "2017-07-06T05:35:53Z")

</div>


