mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 06:33:15 +00:00
|
Some checks failed
Deploy / deploy (push) Has been cancelled
The collector's remote-syslog spool had no rotation, so each gateway's /var/log/remote/<host>/<host>.log grew unbounded. Low risk at the old ~109 events/day, but the gateways now forward ~60k/day. CloudWatch (90d) is the system of record; the local files are only a CW-agent spool, so keep a short 7-day compressed window. copytruncate keeps rsyslog's open dynaFile handles valid (truncate in place). Applied live already; this codifies it so an instance replacement keeps it (mirrors the existing netflow-retention timer). Deploying this user-data change forces an instance replacement (userDataCausesReplacement) — the EIP re-associates and the forwarding target is unchanged, so do it in a window. |
||
|---|---|---|
| .. | ||
| syslog-server-stack.ts | ||