- appender.audit_rolling.type = RollingFile
- appender.audit_rolling.name = audit_rolling
- appender.audit_rolling.fileName = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_access.log
- appender.audit_rolling.layout.type = PatternLayout
- appender.audit_rolling.layout.pattern = [%d{ISO8601}] %m%n
- appender.audit_rolling.filePattern = ${sys:es.logs.base_path}${sys:file.separator}${sys:es.logs.cluster_name}_access-%d{yyyy-MM-dd}.log
- appender.audit_rolling.policies.type = Policies
- appender.audit_rolling.policies.time.type = TimeBasedTriggeringPolicy
- appender.audit_rolling.policies.time.interval = 1
- appender.audit_rolling.policies.time.modulate = true
- logger.xpack_security_audit_logfile.name = org.elasticsearch.xpack.security.audit.logfile.LoggingAuditTrail
- logger.xpack_security_audit_logfile.level = info
- logger.xpack_security_audit_logfile.appenderRef.audit_rolling.ref = audit_rolling
- logger.xpack_security_audit_logfile.additivity = false
|