elasticsearch logs are duplicated in journald
Closed, ResolvedPublic


On Jessie, elasticsearch is started by systemd, which captures console output and sends it to journald. This means that logs are duplicated between /var/log/elasticsearch and syslog / deamon.log.

The log4j configuration should be adapted to log only startup messages or critical messages to console and keep the rest only in the standard elasticsearch logs.

Gehel created this task.Feb 21 2017, 4:29 PM
Restricted Application added a project: Discovery-Search. · View Herald TranscriptFeb 21 2017, 4:29 PM
Restricted Application added a subscriber: Aklapper. · View Herald Transcript
Gehel triaged this task as High priority.Feb 21 2017, 4:29 PM

Change 338998 had a related patch set uploaded (by Gehel):
WIP - elasticsearch: only send minimal logging to console


Gehel added a subscriber: dcausse.Feb 22 2017, 2:22 PM

After discussion with @dcausse, it seems to be a better idea to not send any logs to the console, so as to not mislead people into reading only part of the logs.

Mentioned in SAL (#wikimedia-operations) [2017-02-23T13:52:17Z] <gehel> restart logstash on relforge1001 to test logging configuration - T158664

Change 338998 merged by Gehel:
elasticsearch: don't send logs to the console


Gehel added a comment.Feb 23 2017, 1:58 PM

Change is deployed but will only be active after the next cluster restart.

Gehel edited projects, added Discovery-Search (Current work); removed Discovery-Search.
Gehel moved this task from Backlog to Done on the Discovery-Search (Current work) board.
debt closed this task as Resolved.May 30 2017, 5:33 PM
debt claimed this task.