# Where to Find the Default Location of Elasticsearch Logs for Troubleshooting

> Troubleshoot Elasticsearch issues by locating its default logs. Find logs in /var/log/elasticsearch for package installs or <es-home>/logs for archive installs.

- Repository: [elastic/elasticsearch](https://github.com/elastic/elasticsearch)
- Tags: how-to-guide
- Published: 2026-02-16

---

**Elasticsearch stores logs in `/var/log/elasticsearch` for RPM/Debian package installations or `<es-home>/logs` for archive (tar/zip) installations, determined by the `path.logs` setting which defaults to the `logs` subdirectory of `path.home` as implemented in the Environment class.**

When troubleshooting cluster issues, slow queries, or node failures, locating the default log directory is the first step toward diagnosing problems in the `elastic/elasticsearch` repository. The log location varies based on your installation method and configuration, but the underlying logic resides in the server's environment initialization code.

## How Elasticsearch Determines the Default Log Location

The `Environment` class in [`server/src/main/java/org/elasticsearch/env/Environment.java`](https://github.com/elastic/elasticsearch/blob/main/server/src/main/java/org/elasticsearch/env/Environment.java) handles the resolution of the logs directory. When the `path.logs` setting is not explicitly defined in [`elasticsearch.yml`](https://github.com/elastic/elasticsearch/blob/main/elasticsearch.yml), the code falls back to resolving the logs path relative to the installation home directory:

```java
// From Environment.java lines 20-24
this.logsFile = homeFile.resolve("logs");

```

This means the default location is always the `logs` folder under **`path.home`**, regardless of operating system. The installation packages simply set different default values for `path.home` or override `path.logs` during installation.

## Default Log Locations by Installation Method

While the code logic is consistent, the actual file system path depends on how you installed Elasticsearch.

### RPM and Debian Packages

For Linux package installations (RPM for Red Hat/CentOS, DEB for Debian/Ubuntu), the default logs directory is:

```bash
/var/log/elasticsearch

```

This path is configured during package installation via the default [`elasticsearch.yml`](https://github.com/elastic/elasticsearch/blob/main/elasticsearch.yml) or system environment variables that set `path.logs` to `/var/log/elasticsearch`.

### Archive (tar/zip) and Windows Installations

For archive installations (`.tar.gz` for Linux/Mac, `.zip` for Windows), the default logs directory is relative to the extraction location:

```bash
<es-home>/logs

```

Where `<es-home>` is the directory where you extracted the archive. For example, if you extracted to `/usr/share/elasticsearch`, the logs would be at `/usr/share/elasticsearch/logs`.

## How to Verify the Active Log Location

Rather than guessing based on installation type, you can query the running node to confirm the exact path it is using via the Nodes Info API:

```bash
curl -s "http://localhost:9200/_nodes/settings?filter_path=**.settings.path.logs&pretty"

```

Example response:

```json
{
  "nodes" : {
  "my-node-id" : {
    "settings" : {
      "path" : {
        "logs" : "/var/log/elasticsearch"
      }
    }
  }
  }
}

```

Once confirmed, you can monitor the main log file in real-time:

```bash

# For package installations

tail -f /var/log/elasticsearch/elasticsearch.log

# For archive installations

tail -f /path/to/elasticsearch/logs/elasticsearch.log

```

## Key Log Files for Troubleshooting

Within the logs directory, you will find several distinct log files serving different purposes:

- **`elasticsearch.log`** — The main server log containing cluster state changes, node join/leave events, and general operational messages.
- **`elasticsearch_slowlog.log`** — Contains queries that exceeded the slow search threshold, essential for performance tuning.
- **`elasticsearch_deprecation.log`** — Warnings about deprecated features that will be removed in future versions.
- **GC logs** — Garbage collection logs (named with `gc.log` prefix) tracking JVM memory management.
- **Heap dumps** — Generated during out-of-memory errors, stored in the same directory by default.

According to the JVM settings documentation in [`docs/reference/elasticsearch/jvm-settings.md`](https://github.com/elastic/elasticsearch/blob/main/docs/reference/elasticsearch/jvm-settings.md), both GC logs and heap dump files default to the `path.logs` directory unless explicitly reconfigured via JVM options.

## Summary

- The default **Elasticsearch log location** is determined by the `path.logs` setting, falling back to `homeFile.resolve("logs")` in the `Environment` class.
- **Package installations** (RPM/DEB) default to `/var/log/elasticsearch`.
- **Archive installations** default to `<es-home>/logs`.
- Verify the active path using the `/_nodes/settings` API with the `filter_path=**.settings.path.logs` parameter.
- Key files include `elasticsearch.log`, `elasticsearch_slowlog.log`, and `elasticsearch_deprecation.log`.

## Frequently Asked Questions

### How do I change the default Elasticsearch log directory?

You can override the default location by setting `path.logs` in your [`elasticsearch.yml`](https://github.com/elastic/elasticsearch/blob/main/elasticsearch.yml) configuration file. For example, add `path.logs: /custom/path/to/logs` and restart the node. This setting accepts absolute paths or paths relative to `path.home`.

### What log rotation settings does Elasticsearch use by default?

Elasticsearch uses Log4j2 for logging, with default policies configured in the `log4j2.properties` file within the `config` directory. By default, logs roll over based on size (typically 128MB) and time (daily), retaining the last 7 days of logs. You can customize these settings by editing the Log4j2 configuration.

### Where are Elasticsearch audit logs stored?

Audit logs are stored in the same `path.logs` directory as the main logs, but in a separate file named [`elasticsearch_audit.json`](https://github.com/elastic/elasticsearch/blob/main/elasticsearch_audit.json) (or similar, depending on your configuration). You must explicitly enable audit logging via `xpack.security.audit.enabled: true` in [`elasticsearch.yml`](https://github.com/elastic/elasticsearch/blob/main/elasticsearch.yml) for these logs to be generated.

### Can I view Elasticsearch logs via the API?

While you cannot stream the actual log file contents via the API, you can retrieve the configured log path using the Nodes Info API (`GET /_nodes/settings?filter_path=**.settings.path.logs`). For real-time log analysis, you should use file monitoring tools like `tail`, `cat`, or centralized logging systems like Filebeat to ship logs to Elasticsearch or another monitoring platform.