Where to Find the Default Location of Elasticsearch Logs for Troubleshooting

Elasticsearch stores logs in /var/log/elasticsearch for RPM/Debian package installations or <es-home>/logs for archive (tar/zip) installations, determined by the path.logs setting which defaults to the logs subdirectory of path.home as implemented in the Environment class.

When troubleshooting cluster issues, slow queries, or node failures, locating the default log directory is the first step toward diagnosing problems in the elastic/elasticsearch repository. The log location varies based on your installation method and configuration, but the underlying logic resides in the server's environment initialization code.

How Elasticsearch Determines the Default Log Location

The Environment class in server/src/main/java/org/elasticsearch/env/Environment.java handles the resolution of the logs directory. When the path.logs setting is not explicitly defined in elasticsearch.yml, the code falls back to resolving the logs path relative to the installation home directory:

// From Environment.java lines 20-24
this.logsFile = homeFile.resolve("logs");

This means the default location is always the logs folder under path.home, regardless of operating system. The installation packages simply set different default values for path.home or override path.logs during installation.

Default Log Locations by Installation Method

While the code logic is consistent, the actual file system path depends on how you installed Elasticsearch.

RPM and Debian Packages

For Linux package installations (RPM for Red Hat/CentOS, DEB for Debian/Ubuntu), the default logs directory is:

/var/log/elasticsearch

This path is configured during package installation via the default elasticsearch.yml or system environment variables that set path.logs to /var/log/elasticsearch.

Archive (tar/zip) and Windows Installations

For archive installations (.tar.gz for Linux/Mac, .zip for Windows), the default logs directory is relative to the extraction location:

<es-home>/logs

Where <es-home> is the directory where you extracted the archive. For example, if you extracted to /usr/share/elasticsearch, the logs would be at /usr/share/elasticsearch/logs.

How to Verify the Active Log Location

Rather than guessing based on installation type, you can query the running node to confirm the exact path it is using via the Nodes Info API:

curl -s "http://localhost:9200/_nodes/settings?filter_path=**.settings.path.logs&pretty"

Example response:

{
  "nodes" : {
  "my-node-id" : {
    "settings" : {
      "path" : {
        "logs" : "/var/log/elasticsearch"
      }
    }
  }
  }
}

Once confirmed, you can monitor the main log file in real-time:


# For package installations

tail -f /var/log/elasticsearch/elasticsearch.log

# For archive installations

tail -f /path/to/elasticsearch/logs/elasticsearch.log

Key Log Files for Troubleshooting

Within the logs directory, you will find several distinct log files serving different purposes:

  • elasticsearch.log — The main server log containing cluster state changes, node join/leave events, and general operational messages.
  • elasticsearch_slowlog.log — Contains queries that exceeded the slow search threshold, essential for performance tuning.
  • elasticsearch_deprecation.log — Warnings about deprecated features that will be removed in future versions.
  • GC logs — Garbage collection logs (named with gc.log prefix) tracking JVM memory management.
  • Heap dumps — Generated during out-of-memory errors, stored in the same directory by default.

According to the JVM settings documentation in docs/reference/elasticsearch/jvm-settings.md, both GC logs and heap dump files default to the path.logs directory unless explicitly reconfigured via JVM options.

Summary

  • The default Elasticsearch log location is determined by the path.logs setting, falling back to homeFile.resolve("logs") in the Environment class.
  • Package installations (RPM/DEB) default to /var/log/elasticsearch.
  • Archive installations default to <es-home>/logs.
  • Verify the active path using the /_nodes/settings API with the filter_path=**.settings.path.logs parameter.
  • Key files include elasticsearch.log, elasticsearch_slowlog.log, and elasticsearch_deprecation.log.

Frequently Asked Questions

How do I change the default Elasticsearch log directory?

You can override the default location by setting path.logs in your elasticsearch.yml configuration file. For example, add path.logs: /custom/path/to/logs and restart the node. This setting accepts absolute paths or paths relative to path.home.

What log rotation settings does Elasticsearch use by default?

Elasticsearch uses Log4j2 for logging, with default policies configured in the log4j2.properties file within the config directory. By default, logs roll over based on size (typically 128MB) and time (daily), retaining the last 7 days of logs. You can customize these settings by editing the Log4j2 configuration.

Where are Elasticsearch audit logs stored?

Audit logs are stored in the same path.logs directory as the main logs, but in a separate file named elasticsearch_audit.json (or similar, depending on your configuration). You must explicitly enable audit logging via xpack.security.audit.enabled: true in elasticsearch.yml for these logs to be generated.

Can I view Elasticsearch logs via the API?

While you cannot stream the actual log file contents via the API, you can retrieve the configured log path using the Nodes Info API (GET /_nodes/settings?filter_path=**.settings.path.logs). For real-time log analysis, you should use file monitoring tools like tail, cat, or centralized logging systems like Filebeat to ship logs to Elasticsearch or another monitoring platform.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →