# Zipping log files once they reach a threshold of 1 Gb

**URL:** <https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078>\
**Category:** Elasticsearch\
**Created:** [July 23, 2018, 5:57am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078 "2018-07-23T05:57:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sakshi\_Aggarwal](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@Sakshi\_Aggarwal](https://discuss.elastic.co/u/Sakshi_Aggarwal)\
**Post date:** [July 23, 2018, 5:57am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/1 "2018-07-23T05:57:13Z")

</div>

Hello Everyone!

We are taking logs from around 50 machines throughout the day . So we need to reduce the size of the log files.  
I wanted to ask if we can zip the log files once they become so many in number that they require large space .  
Or any other alternate except for zipping.

Thank you 🙂

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 23, 2018, 7:07am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/2 "2018-07-23T07:07:17Z")

</div>

I'm not sure your question is related to elasticsearch.

Which logs files are you talking about ?

---

<div class="post-metadata">

**Author:** ![Sakshi\_Aggarwal](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@Sakshi\_Aggarwal](https://discuss.elastic.co/u/Sakshi_Aggarwal)\
**Post date:** [July 23, 2018, 7:15am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/3 "2018-07-23T07:15:09Z")

</div>

On the process of importing files from remote machines , the system with elastic search and logstash configuration has large indices . So ,

1. If via any of elastic search means , is there any option to zip and reduce the memory utilized by indices?
2. If by any means , I can delete old logs which are now not useful for me ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 23, 2018, 7:28am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/4 "2018-07-23T07:28:31Z")

</div>

You can change the compression of indices you are writing to anymore (old indices) and also use force merge.  
You can just delete indices you are not using anymore (very old indices).

To automate all that, I'd suggest to look at the curator tool.

---

<div class="post-metadata">

**Author:** ![Sakshi\_Aggarwal](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@Sakshi\_Aggarwal](https://discuss.elastic.co/u/Sakshi_Aggarwal)\
**Post date:** [July 23, 2018, 7:38am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/5 "2018-07-23T07:38:51Z")

</div>

Thanks, I am checking out the curator tool.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 23, 2018, 7:42am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/6 "2018-07-23T07:42:37Z")

</div>

You may also want to look at [this guide in the documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/tune-for-disk-usage.html).

---

<div class="post-metadata">

**Author:** ![Sakshi\_Aggarwal](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@Sakshi\_Aggarwal](https://discuss.elastic.co/u/Sakshi_Aggarwal)\
**Post date:** [July 26, 2018, 9:19am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/7 "2018-07-26T09:19:18Z")

</div>

How can we archive and un-archive the data to reduce active search Database.  
Explanation :  
Via this query i meant to ask that if there is an option to keep the logs kind of active and passive based on the time duration . For example If i want to keep my logs of last one year in my active state i.e. Anytime available on Kibana while i want the rest of the previous logs consuming the least of my memory being in passive state.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 26, 2018, 9:21am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/8 "2018-07-26T09:21:42Z")

</div>

You may be able to [close older indices](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/indices-open-close.html), although that means you will need to explicitly open them again if you want to search them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2018, 9:21am UTC](https://discuss.elastic.co/t/zipping-log-files-once-they-reach-a-threshold-of-1-gb/141078/9 "2018-08-23T09:21:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
