Q: Application logs are written to syslog, but the logs for your specific application are mixed with system messages in `/var/log/messages`. How do you configure rsyslog to send your application's logs to a separate file?
rsyslog is the standard syslog implementation on most Linux distributions. It uses rules in /etc/rsyslog.conf or /etc/rsyslog.d/.conf to ...
#Linux #Allow user 'deploy' to restart nginx and read syslog only #L2 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""We encountered this OS-level bottleneck during peak traffic and diagnosed it down to kernel and filesystem metrics. The interviewer is testing: Syslog configuration, log routing, rsyslog filters.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
rsyslog is the standard syslog implementation on most Linux distributions. It uses rules in /etc/rsyslog.conf or /etc/rsyslog.d/*.conf to route log messages based on facility, severity, or program name.
- Create a filter rule in
/etc/rsyslog.d/myapp.conf: - Alternative using facility:
- Restart rsyslog:
systemctl restart rsyslog
2️⃣
Remediation & Permanent Safeguards
To separate your application's logs: The & stop directive prevents the message from also being written to /var/log/messages. If the app uses local0 facility:
# Route all messages from 'myapp' to its own file
if $programname == 'myapp' then /var/log/myapp.log
& stop
- Set up logrotate for the new file in
/etc/logrotate.d/myapp:
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Create a filter rule in /etc/rsyslog.d/myapp.conf:."
⚡ 60-Second Elevator Pitch Talking Points
- Create a filter rule in /etc/rsyslog.d/myapp.conf:
- Alternative using facility:
- Restart rsyslog: systemctl restart rsyslog
Advertisement