⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] Linux Allow user 'deploy' to restart nginx and read syslog only Production Scenario [L2]

Q: Application logs are written to syslog, but the logs for your specific application are mixed with system messages in `/var/log/messages`. How do you configure rsyslog to send your application's logs to a separate file?

rsyslog is the standard syslog implementation on most Linux distributions. It uses rules in /etc/rsyslog.conf or /etc/rsyslog.d/.conf to ...

#Linux #Allow user 'deploy' to restart nginx and read syslog only #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""We encountered this OS-level bottleneck during peak traffic and diagnosed it down to kernel and filesystem metrics. The interviewer is testing: Syslog configuration, log routing, rsyslog filters.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

rsyslog is the standard syslog implementation on most Linux distributions. It uses rules in /etc/rsyslog.conf or /etc/rsyslog.d/*.conf to route log messages based on facility, severity, or program name.

  • Create a filter rule in /etc/rsyslog.d/myapp.conf:
  • Alternative using facility:
  • Restart rsyslog: systemctl restart rsyslog
2️⃣

Remediation & Permanent Safeguards

To separate your application's logs: The & stop directive prevents the message from also being written to /var/log/messages. If the app uses local0 facility:

# Route all messages from 'myapp' to its own file
   if $programname == 'myapp' then /var/log/myapp.log
   & stop
  • Set up logrotate for the new file in /etc/logrotate.d/myapp:
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Create a filter rule in /etc/rsyslog.d/myapp.conf:."
⚡ 60-Second Elevator Pitch Talking Points
  • Create a filter rule in /etc/rsyslog.d/myapp.conf:
  • Alternative using facility:
  • Restart rsyslog: systemctl restart rsyslog
Advertisement
Want more Linux scenarios?
Explore our complete collection of scenario-based Linux interview runbooks.
Browse All Linux Questions →

📚 Related Production Scenarios in Linux