# Where to change location of the logstash log file

**URL:** <https://discuss.elastic.co/t/where-to-change-location-of-the-logstash-log-file/56190>\
**Category:** Logstash\
**Created:** [July 22, 2016, 2:49pm UTC](https://discuss.elastic.co/t/where-to-change-location-of-the-logstash-log-file/56190 "2016-07-22T14:49:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 22, 2016, 2:49pm UTC](https://discuss.elastic.co/t/where-to-change-location-of-the-logstash-log-file/56190/1 "2016-07-22T14:49:16Z")

</div>

can't find the way to change default location for logstash log file. Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 22, 2016, 3:38pm UTC](https://discuss.elastic.co/t/where-to-change-location-of-the-logstash-log-file/56190/2 "2016-07-22T15:38:49Z")

</div>

In the end Logstash logs to the file passed to it via the `-l`/`--log` option. Depending on how you run Logstash there are different ways of affecting the command line. For RPM/Debian setups you'll want to adjust /etc/sysconfig/logstash or /etc/default/logstash.

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 22, 2016, 5:22pm UTC](https://discuss.elastic.co/t/where-to-change-location-of-the-logstash-log-file/56190/3 "2016-07-22T17:22:17Z")

</div>

I have both cases - in some it is run as service (sudo root available) - and in other I am running it from non-root account - not as a service but as nohup process ... SO for service the sysconfig file seems to exist on my RHEL 7 so that would be a place to setup it up/change it; For nohup option I would presume all goes out to output file for the nohup process?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 22, 2016, 5:29pm UTC](https://discuss.elastic.co/t/where-to-change-location-of-the-logstash-log-file/56190/4 "2016-07-22T17:29:44Z")

</div>

Why would you run Logstash via nohup?

> For nohup option I would presume all goes out to output file for the nohup process?

Yes. Unless, as I said, the `-l`/`--log` option is passed.

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 22, 2016, 5:41pm UTC](https://discuss.elastic.co/t/where-to-change-location-of-the-logstash-log-file/56190/5 "2016-07-22T17:41:18Z")

</div>

.. using nohup in VMs where there is no sudo root access available / hard to get ...

I get it - thank you Magnus.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:46am UTC](https://discuss.elastic.co/t/where-to-change-location-of-the-logstash-log-file/56190/6 "2017-07-06T04:46:49Z")

</div>


