# Graylog.audit\_log is more than 4 GB

**URL:** <https://community.graylog.org/t/graylog-audit-log-is-more-than-4-gb/24419>\
**Category:** Graylog Central (peer support)\
**Created:** [June 21, 2022, 9:32pm UTC](https://community.graylog.org/t/graylog-audit-log-is-more-than-4-gb/24419 "2022-06-21T21:32:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![MKramis](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/mkramis/32/2220_2.png) [@MKramis](https://community.graylog.org/u/MKramis)\
**Post date:** [June 21, 2022, 9:32pm UTC](https://community.graylog.org/t/graylog-audit-log-is-more-than-4-gb/24419/1 "2022-06-21T21:32:47Z")

</div>

Dear graylog community,

we have a long running Graylog setup that is currently running Version 4.2.5.  
As we plan to upgrade the setup first to version 4.2.9 we observed that our table of graylog.audit\_log is more than 4 GB in size.

Is there some way to have a housekeeping on this table? Is this part of a newer Version of Graylog? Did you have a prepared query to delete everything that is older than a month?

Second question:  
We have our Elasticsearch cluster updated to Version 7.11.1. Taking license topics out of the game, to what version can we upgrade elasticsearch that Graylog can still work an communicate and work with it?  
If there is no-way to continue using elasticsearch, is there a way of migration or path of migration that you can recommend? Most important is easy migration and keeping all data in place.

Thank you for the support

BR, Markus

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [June 22, 2022, 10:21pm UTC](https://community.graylog.org/t/graylog-audit-log-is-more-than-4-gb/24419/2 "2022-06-22T22:21:38Z")

</div>

Hello,

> [@MKramis](#):
>
> Is there some way to have a housekeeping on this table? Is this part of a newer Version of Graylog? Did you have a prepared query to delete everything that is older than a month?

Not that I’m aware of, perhaps check your log4j2.xml file.

> [@MKramis](#):
>
> We have our Elasticsearch cluster updated to Version 7.11.1. Taking license topics out of the game, to what version can we upgrade elasticsearch that Graylog can still work an communicate and work with it?  
> If there is no-way to continue using elasticsearch, is there a way of migration or path of migration that you can recommend? Most important is easy migration and keeping all data in place.

To sum this up, reason for OpenSearch is elasticsearch-oss.7.10.x would match elasticsearch.7.10.x version. Elasticsearch-oss.7.10.x is now AWS little baby and things might change over time (i.e. name conventions, etc…) Testing this out would be awesome and filling us in would be great. Be aware of issues.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 6, 2022, 10:22pm UTC](https://community.graylog.org/t/graylog-audit-log-is-more-than-4-gb/24419/3 "2022-07-06T22:22:04Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
