CLASSIFICATION: UNCLASSIFIED
Hello,
So here's what currently is configured in our .conf file:
destination syslog { file("/var/log/syslog.log" perm(0644)); };
what you are saying, is if I want logs to rotate on daily basis, I can just make the above line to read as following:
destination syslog { file("/var/log/syslog-${YEAR}-${MONTH}-${DAY}.log"); };
Thanks
Jitesh Amin
CLASSIFICATION: UNCLASSIFIED
-----Original Message-----
From: Gergely Nagy <algernon@balabit.com>
Sent: Wednesday, May 30, 2018 7:25 AM
To: Amin, Jitesh CTR DISA JSP (US) <jitesh.amin.ctr@mail.mil>; syslog-ng@lists.balabit.hu
Subject: [Non-DoD Source] Re: [syslog-ng] (U) Rotate syslog-ng log files
All active links contained in this email were disabled. Please verify the identity of the sender, and confirm the authenticity of all links contained within the message prior to copying and pasting the address to a Web browser.
----
Hi!
>>>>> "Amin" == Amin, Jitesh CTR DISA JSP (US) <jitesh.amin.ctr@mail.mil> writes:
Amin> What we are trying to do is rotate the syslog.log file once it
Amin> reaches 500 MB (as well as looking into rotating file every 24
Amin> hours)? Once the log file rotates, it creates a new file named
Amin> syslog.log.0 and so on..
syslog-ng does not support size-based rotation, you'll have to configure logrotate for that. See the packaging/debian/syslog-ng-core.syslog-ng.logrotate[1] file for an example.
[1]: Caution-https://github.com/balabit/syslog-ng/blob/master/ packaging/debian/syslog-ng- core.syslog-ng.logrotate
With logrotate, the most recent logfile syslog-ng writes to will always be syslog.log, and the rotated files will have different names - depending on the logrotate configuration you use.
For time-based, daily rotation, you can use templates in the destination filename, such as:
destination d_syslog {
file("/var/log/syslog-${YEAR}-${MONTH}-${DAY}.log");
};
Hope this helps!
--
|8]
____________________________________________________________ __________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/? product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq