# Where is ES log file?

**URL:** <https://discuss.elastic.co/t/where-is-es-log-file/72599>\
**Category:** Elasticsearch\
**Created:** [January 24, 2017, 9:27am UTC](https://discuss.elastic.co/t/where-is-es-log-file/72599 "2017-01-24T09:27:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![AmazoneWebService](https://avatars.discourse-cdn.com/v4/letter/a/e19adc/32.png) [@AmazoneWebService](https://discuss.elastic.co/u/AmazoneWebService)\
**Post date:** [January 24, 2017, 9:27am UTC](https://discuss.elastic.co/t/where-is-es-log-file/72599/1 "2017-01-24T09:27:26Z")

</div>

I install ES 2.3.3, and then start elasticsearch  
but Active status is failed.  
so i want to see log file.  
but in /var/lib/elasticsearch folder. there are no log file. ☹

is any other folder?

# this is log message

elasticsearch.service - Elasticsearch  
Loaded: loaded (/usr/lib/systemd/system/elasticsearch.service; disabled; vendor preset: disabled)  
Active: failed (Result: exit-code) since Tue 2017-01-24 09:23:31 UTC; 4s ago  
Docs: [http://www.elastic.co](http://www.elastic.co)  
Process: 16790 ExecStart=/usr/share/elasticsearch/bin/elasticsearch -Des.pidfile=${PID\_DIR}/elasticsearch.pid -Des.default.path.home=${ES\_HOME} -Des.default.path.logs=${LOG\_DIR} -Des.default.path.data=${DATA\_DIR} -Des.default.path.conf=${CONF\_DIR} (code=exited, status=1/FAILURE)  
Process: 16788 ExecStartPre=/usr/share/elasticsearch/bin/elasticsearch-systemd-pre-exec (code=exited, status=0/SUCCESS)  
Main PID: 16790 (code=exited, status=1/FAILURE)

Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal elasticsearch[16790]: at java.nio.file.Files.newInputStream(Files.java:152)  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal elasticsearch[16790]: at org.elasticsearch.common.settings.Settings$Builder.loadFromPath(Settings.java:1067)  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal elasticsearch[16790]: at org.elasticsearch.node.internal.InternalSettingsPreparer.prepareEnvironment(InternalSettingsPreparer.java:88)  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal elasticsearch[16790]: at org.elasticsearch.bootstrap.Bootstrap.initialSettings(Bootstrap.java:202)  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal elasticsearch[16790]: at org.elasticsearch.bootstrap.Bootstrap.init(Bootstrap.java:241)  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal elasticsearch[16790]: at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:35)  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal elasticsearch[16790]: Refer to the log for complete error details.  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal systemd[1]: elasticsearch.service: main process exited, code=exited, status=1/FAILURE  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal systemd[1]: Unit elasticsearch.service entered failed state.  
Jan 24 09:23:31 ip-192-168-100-168.ap-northeast-2.compute.internal systemd[1]: elasticsearch.service failed.

---

<div class="post-metadata">

**Author:** ![xavierfacq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavierfacq/32/8744_2.png) [@xavierfacq](https://discuss.elastic.co/u/xavierfacq)\
**Post date:** [January 24, 2017, 11:55am UTC](https://discuss.elastic.co/t/where-is-es-log-file/72599/2 "2017-01-24T11:55:56Z")

</div>

Try to check the folder /var/log/elasticsearch/

You can read the end of /var/log/message to have details on the system errors.

---

<div class="post-metadata">

**Author:** ![AmazoneWebService](https://avatars.discourse-cdn.com/v4/letter/a/e19adc/32.png) [@AmazoneWebService](https://discuss.elastic.co/u/AmazoneWebService)\
**Post date:** [January 24, 2017, 11:58am UTC](https://discuss.elastic.co/t/where-is-es-log-file/72599/3 "2017-01-24T11:58:27Z")

</div>

i wrote incorrectly.

i already saw log folder.  
/var/log/elasticsearch

---

<div class="post-metadata">

**Author:** ![xavierfacq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavierfacq/32/8744_2.png) [@xavierfacq](https://discuss.elastic.co/u/xavierfacq)\
**Post date:** [January 24, 2017, 12:00pm UTC](https://discuss.elastic.co/t/where-is-es-log-file/72599/4 "2017-01-24T12:00:49Z")

</div>

Can you provide more informations about:

- the OS
- how did you install
- how do you start the service
- everything you think usefull

---

<div class="post-metadata">

**Author:** ![AmazoneWebService](https://avatars.discourse-cdn.com/v4/letter/a/e19adc/32.png) [@AmazoneWebService](https://discuss.elastic.co/u/AmazoneWebService)\
**Post date:** [January 25, 2017, 12:52am UTC](https://discuss.elastic.co/t/where-is-es-log-file/72599/5 "2017-01-25T00:52:24Z")

</div>

i used

- centos7
- repository install (yum install elasticsearch-2.3.3)
- service elasticsearch start
- check status : service elasticsearch status

I was using ES5.1 version and will test it in 2.3 version, so i deleted the 5.1 and updated the 2.3  
ant then this issue has occurred.

---

<div class="post-metadata">

**Author:** ![AmazoneWebService](https://avatars.discourse-cdn.com/v4/letter/a/e19adc/32.png) [@AmazoneWebService](https://discuss.elastic.co/u/AmazoneWebService)\
**Post date:** [January 25, 2017, 3:19am UTC](https://discuss.elastic.co/t/where-is-es-log-file/72599/6 "2017-01-25T03:19:41Z")

</div>

The cause is unknown, but it is resolved.  
just delete the instance, and install new~!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2017, 3:19am UTC](https://discuss.elastic.co/t/where-is-es-log-file/72599/7 "2017-02-22T03:19:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
