mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 06:33:15 +00:00
fix(syslog-server): rotate /var/log/remote so the disk can't fill (INFRA-11) (#2)
Some checks failed
Deploy / deploy (push) Has been cancelled
Some checks failed
Deploy / deploy (push) Has been cancelled
The collector's remote-syslog spool had no rotation, so each gateway's /var/log/remote/<host>/<host>.log grew unbounded. Low risk at the old ~109 events/day, but the gateways now forward ~60k/day. CloudWatch (90d) is the system of record; the local files are only a CW-agent spool, so keep a short 7-day compressed window. copytruncate keeps rsyslog's open dynaFile handles valid (truncate in place). Applied live already; this codifies it so an instance replacement keeps it (mirrors the existing netflow-retention timer). Deploying this user-data change forces an instance replacement (userDataCausesReplacement) — the EIP re-associates and the forwarding target is unchanged, so do it in a window.
This commit is contained in:
parent
97bc751782
commit
6d52b246b1
1 changed files with 16 additions and 0 deletions
|
|
@ -115,6 +115,22 @@ export class SyslogServerStack extends cdk.Stack {
|
|||
"systemctl enable rsyslog",
|
||||
"systemctl restart rsyslog",
|
||||
"",
|
||||
"# ── Rotate /var/log/remote so it can't grow unbounded ──",
|
||||
"# CloudWatch (90d) is the system of record; these local files are just a",
|
||||
"# spool for the CW agent, so keep only a short window. copytruncate keeps",
|
||||
"# rsyslog's open dynaFile handles valid (truncate in place, same inode).",
|
||||
"cat > /etc/logrotate.d/remote-syslog <<'EOF'",
|
||||
"/var/log/remote/*/*.log {",
|
||||
" daily",
|
||||
" rotate 7",
|
||||
" compress",
|
||||
" delaycompress",
|
||||
" missingok",
|
||||
" notifempty",
|
||||
" copytruncate",
|
||||
"}",
|
||||
"EOF",
|
||||
"",
|
||||
"# ── CloudWatch agent: ship /var/log/remote/**/*.log to unifi-syslog ──",
|
||||
"dnf install -y amazon-cloudwatch-agent",
|
||||
"cat > /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.json <<'EOF'",
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue