2016-04-03 10:09:24 -04:00
|
|
|
[[settings]]
|
|
|
|
== Configuring Elasticsearch
|
2014-06-12 07:56:06 -04:00
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
Elasticsearch ships with good defaults and requires very little configuration.
|
|
|
|
Most settings can be changed on a running cluster using the
|
|
|
|
<<cluster-update-settings>> API.
|
2013-10-17 05:54:36 -04:00
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
The configuration files should contain settings which are node-specific (such
|
|
|
|
as `node.name` and paths), or settings which a node requires in order to be
|
|
|
|
able to join a cluster, such as `cluster.name` and `network.host`.
|
2014-11-21 15:41:06 -05:00
|
|
|
|
2013-09-30 17:32:00 -04:00
|
|
|
[float]
|
2016-04-03 10:09:24 -04:00
|
|
|
=== Config file location
|
2014-05-02 04:44:26 -04:00
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
Elasticsearch has two configuration files:
|
2014-05-14 10:01:25 -04:00
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
* `elasticsearch.yml` for configuring Elasticsearch, and
|
2016-08-31 15:51:52 -04:00
|
|
|
* `log4j2.properties` for configuring Elasticsearch logging.
|
2014-05-14 10:01:25 -04:00
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
These files are located in the config directory, whose location defaults to
|
|
|
|
`$ES_HOME/config/`. The Debian and RPM packages set the config directory
|
|
|
|
location to `/etc/elasticsearch/`.
|
2014-05-14 10:01:25 -04:00
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
The location of the config directory can be changed with the `path.conf`
|
|
|
|
setting, as follows:
|
2014-05-14 10:01:25 -04:00
|
|
|
|
|
|
|
[source,sh]
|
2016-04-03 10:09:24 -04:00
|
|
|
-------------------------------
|
2016-06-30 10:42:01 -04:00
|
|
|
./bin/elasticsearch -Epath.conf=/path/to/my/config/
|
2016-04-03 10:09:24 -04:00
|
|
|
-------------------------------
|
2013-08-28 19:24:34 -04:00
|
|
|
|
|
|
|
[float]
|
2016-04-03 10:09:24 -04:00
|
|
|
=== Config file format
|
2013-08-28 19:24:34 -04:00
|
|
|
|
|
|
|
The configuration format is http://www.yaml.org/[YAML]. Here is an
|
2016-04-03 10:09:24 -04:00
|
|
|
example of changing the path of the data and logs directories:
|
2013-08-28 19:24:34 -04:00
|
|
|
|
2013-10-17 05:54:36 -04:00
|
|
|
[source,yaml]
|
2013-08-28 19:24:34 -04:00
|
|
|
--------------------------------------------------
|
|
|
|
path:
|
2016-04-03 10:09:24 -04:00
|
|
|
data: /var/lib/elasticsearch
|
2016-05-12 16:42:27 -04:00
|
|
|
logs: /var/log/elasticsearch
|
2013-08-28 19:24:34 -04:00
|
|
|
--------------------------------------------------
|
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
Settings can also be flattened as follows:
|
2013-08-28 19:24:34 -04:00
|
|
|
|
2013-10-17 05:54:36 -04:00
|
|
|
[source,yaml]
|
2013-08-28 19:24:34 -04:00
|
|
|
--------------------------------------------------
|
2016-04-03 10:09:24 -04:00
|
|
|
path.data: /var/lib/elasticsearch
|
2016-05-12 16:42:27 -04:00
|
|
|
path.logs: /var/log/elasticsearch
|
2013-08-28 19:24:34 -04:00
|
|
|
--------------------------------------------------
|
|
|
|
|
|
|
|
[float]
|
2017-05-19 10:49:56 -04:00
|
|
|
=== Environment variable substitution
|
2013-08-28 19:24:34 -04:00
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
Environment variables referenced with the `${...}` notation within the
|
|
|
|
configuration file will be replaced with the value of the environment
|
|
|
|
variable, for instance:
|
2013-08-28 19:24:34 -04:00
|
|
|
|
2013-10-17 05:54:36 -04:00
|
|
|
[source,yaml]
|
2013-08-28 19:24:34 -04:00
|
|
|
--------------------------------------------------
|
2016-04-03 10:09:24 -04:00
|
|
|
node.name: ${HOSTNAME}
|
|
|
|
network.host: ${ES_NETWORK_HOST}
|
2013-08-28 19:24:34 -04:00
|
|
|
--------------------------------------------------
|
|
|
|
|
|
|
|
[float]
|
2016-04-03 10:09:24 -04:00
|
|
|
=== Prompting for settings
|
2013-08-28 19:24:34 -04:00
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
For settings that you do not wish to store in the configuration file, you can
|
|
|
|
use the value `${prompt.text}` or `${prompt.secret}` and start Elasticsearch
|
|
|
|
in the foreground. `${prompt.secret}` has echoing disabled so that the value
|
|
|
|
entered will not be shown in your terminal; `${prompt.text}` will allow you to
|
|
|
|
see the value as you type it in. For example:
|
2015-04-30 13:14:05 -04:00
|
|
|
|
|
|
|
[source,yaml]
|
|
|
|
--------------------------------------------------
|
|
|
|
node:
|
2015-06-06 10:41:07 -04:00
|
|
|
name: ${prompt.text}
|
2015-04-30 13:14:05 -04:00
|
|
|
--------------------------------------------------
|
|
|
|
|
2016-04-03 10:09:24 -04:00
|
|
|
When starting Elasticsearch, you will be prompted to enter the actual value
|
|
|
|
like so:
|
2015-04-30 13:14:05 -04:00
|
|
|
|
|
|
|
[source,sh]
|
|
|
|
--------------------------------------------------
|
|
|
|
Enter value for [node.name]:
|
|
|
|
--------------------------------------------------
|
|
|
|
|
2015-06-06 10:41:07 -04:00
|
|
|
NOTE: Elasticsearch will not start if `${prompt.text}` or `${prompt.secret}`
|
2015-04-30 13:14:05 -04:00
|
|
|
is used in the settings and the process is run as a service or in the background.
|
|
|
|
|
2013-08-28 19:24:34 -04:00
|
|
|
[float]
|
2013-09-25 12:17:40 -04:00
|
|
|
[[logging]]
|
2016-04-03 10:09:24 -04:00
|
|
|
== Logging configuration
|
2013-08-28 19:24:34 -04:00
|
|
|
|
2017-02-16 12:18:22 -05:00
|
|
|
Elasticsearch uses https://logging.apache.org/log4j/2.x/[Log4j 2] for
|
2016-08-31 15:51:52 -04:00
|
|
|
logging. Log4j 2 can be configured using the log4j2.properties
|
2017-02-16 19:00:08 -05:00
|
|
|
file. Elasticsearch exposes three properties, `${sys:es.logs.base_path}`,
|
2017-02-16 12:17:27 -05:00
|
|
|
`${sys:es.logs.cluster_name}`, and `${sys:es.logs.node_name}` (if the node name
|
2017-01-16 07:39:37 -05:00
|
|
|
is explicitly set via `node.name`) that can be referenced in the configuration
|
|
|
|
file to determine the location of the log files. The property
|
|
|
|
`${sys:es.logs.base_path}` will resolve to the log directory,
|
|
|
|
`${sys:es.logs.cluster_name}` will resolve to the cluster name (used as the
|
|
|
|
prefix of log filenames in the default configuration), and
|
|
|
|
`${sys:es.logs.node_name}` will resolve to the node name (if the node name is
|
|
|
|
explicitly set).
|
2016-08-31 15:51:52 -04:00
|
|
|
|
|
|
|
For example, if your log directory (`path.logs`) is `/var/log/elasticsearch` and
|
2017-01-16 07:39:37 -05:00
|
|
|
your cluster is named `production` then `${sys:es.logs.base_path}` will resolve
|
|
|
|
to `/var/log/elasticsearch` and
|
|
|
|
`${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}.log`
|
|
|
|
will resolve to `/var/log/elasticsearch/production.log`.
|
2014-11-12 11:39:10 -05:00
|
|
|
|
2016-08-31 15:51:52 -04:00
|
|
|
[source,properties]
|
|
|
|
--------------------------------------------------
|
|
|
|
appender.rolling.type = RollingFile <1>
|
|
|
|
appender.rolling.name = rolling
|
2017-01-16 07:39:37 -05:00
|
|
|
appender.rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}.log <2>
|
2016-08-31 15:51:52 -04:00
|
|
|
appender.rolling.layout.type = PatternLayout
|
|
|
|
appender.rolling.layout.pattern = [%d{ISO8601}][%-5p][%-25c] %.10000m%n
|
2017-01-16 07:39:37 -05:00
|
|
|
appender.rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}-%d{yyyy-MM-dd}.log <3>
|
2016-08-31 15:51:52 -04:00
|
|
|
appender.rolling.policies.type = Policies
|
|
|
|
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy <4>
|
|
|
|
appender.rolling.policies.time.interval = 1 <5>
|
|
|
|
appender.rolling.policies.time.modulate = true <6>
|
|
|
|
--------------------------------------------------
|
|
|
|
|
|
|
|
<1> Configure the `RollingFile` appender
|
|
|
|
<2> Log to `/var/log/elasticsearch/production.log`
|
|
|
|
<3> Roll logs to `/var/log/elasticsearch/production-yyyy-MM-dd.log`
|
|
|
|
<4> Using a time-based roll policy
|
|
|
|
<5> Roll logs on a daily basis
|
|
|
|
<6> Align rolls on the day boundary (as opposed to rolling every twenty-four
|
|
|
|
hours)
|
|
|
|
|
2017-04-20 07:29:21 -04:00
|
|
|
NOTE: Log4j's configuration parsing gets confused by any extraneous whitespace;
|
2017-04-20 07:34:16 -04:00
|
|
|
if you copy and paste any Log4j settings on this page, or enter any Log4j
|
|
|
|
configuration in general, be sure to trim any leading and trailing whitespace.
|
2017-04-20 07:29:21 -04:00
|
|
|
|
2016-08-31 15:51:52 -04:00
|
|
|
If you append `.gz` or `.zip` to `appender.rolling.filePattern`, then the logs
|
|
|
|
will be compressed as they are rolled.
|
|
|
|
|
2017-01-16 07:39:37 -05:00
|
|
|
If you want to retain log files for a specified period of time, you can use a
|
|
|
|
rollover strategy with a delete action.
|
|
|
|
|
|
|
|
[source,properties]
|
|
|
|
--------------------------------------------------
|
|
|
|
appender.rolling.strategy.type = DefaultRolloverStrategy <1>
|
|
|
|
appender.rolling.strategy.action.type = Delete <2>
|
|
|
|
appender.rolling.strategy.action.basepath = ${sys:es.logs.base_path} <3>
|
|
|
|
appender.rolling.strategy.action.condition.type = IfLastModified <4>
|
|
|
|
appender.rolling.strategy.action.condition.age = 7D <5>
|
|
|
|
appender.rolling.strategy.action.PathConditions.type = IfFileName <6>
|
|
|
|
appender.rolling.strategy.action.PathConditions.glob = ${sys:es.logs.cluster_name}-* <7>
|
|
|
|
--------------------------------------------------
|
|
|
|
|
|
|
|
<1> Configure the `DefaultRolloverStrategy`
|
|
|
|
<2> Configure the `Delete` action for handling rollovers
|
|
|
|
<3> The base path to the Elasticsearch logs
|
|
|
|
<4> The condition to apply when handling rollovers
|
|
|
|
<5> Retain logs for seven days
|
|
|
|
<6> Only delete files older than seven days if they match the specified glob
|
|
|
|
<7> Delete files from the base path matching the glob
|
|
|
|
`${sys:es.logs.cluster_name}-*`; this is the glob that log files are rolled
|
|
|
|
to; this is needed to only delete the rolled Elasticsearch logs but not also
|
|
|
|
delete the deprecation and slow logs
|
|
|
|
|
2016-08-31 15:51:52 -04:00
|
|
|
Multiple configuration files can be loaded (in which case they will get merged)
|
|
|
|
as long as they are named `log4j2.properties` and have the Elasticsearch config
|
|
|
|
directory as an ancestor; this is useful for plugins that expose additional
|
2016-09-14 08:08:49 -04:00
|
|
|
loggers. The logger section contains the java packages and their corresponding
|
|
|
|
log level. The appender section contains the destinations for the logs.
|
|
|
|
Extensive information on how to customize logging and all the supported
|
|
|
|
appenders can be found on the
|
2016-08-31 15:51:52 -04:00
|
|
|
http://logging.apache.org/log4j/2.x/manual/configuration.html[Log4j
|
|
|
|
documentation].
|
2015-05-26 11:44:52 -04:00
|
|
|
|
2015-05-26 12:16:12 -04:00
|
|
|
[float]
|
2016-08-31 15:51:52 -04:00
|
|
|
[[deprecation-logging]]
|
2016-04-03 10:09:24 -04:00
|
|
|
=== Deprecation logging
|
2015-05-26 11:44:52 -04:00
|
|
|
|
|
|
|
In addition to regular logging, Elasticsearch allows you to enable logging
|
|
|
|
of deprecated actions. For example this allows you to determine early, if
|
|
|
|
you need to migrate certain functionality in the future. By default,
|
2016-08-31 10:51:17 -04:00
|
|
|
deprecation logging is enabled at the WARN level, the level at which all
|
|
|
|
deprecation log messages will be emitted.
|
2015-05-26 11:44:52 -04:00
|
|
|
|
2016-08-31 15:51:52 -04:00
|
|
|
[source,properties]
|
2015-05-26 11:44:52 -04:00
|
|
|
--------------------------------------------------
|
2016-08-31 15:51:52 -04:00
|
|
|
logger.deprecation.level = warn
|
2015-05-26 11:44:52 -04:00
|
|
|
--------------------------------------------------
|
|
|
|
|
|
|
|
This will create a daily rolling deprecation log file in your log directory.
|
|
|
|
Check this file regularly, especially when you intend to upgrade to a new
|
|
|
|
major version.
|
2016-08-31 10:51:17 -04:00
|
|
|
|
2016-09-01 14:25:04 -04:00
|
|
|
The default logging configuration has set the roll policy for the deprecation
|
|
|
|
logs to roll and compress after 1 GB, and to preserve a maximum of five log
|
|
|
|
files (four rolled logs, and the active log).
|
|
|
|
|
2016-08-31 15:51:52 -04:00
|
|
|
You can disable it in the `config/log4j2.properties` file by setting the deprecation
|
2016-11-15 11:57:26 -05:00
|
|
|
log level to `error`.
|