Home
Docs
Join the conversation
Join Slack
Channels
# arm-architecture
# code-review
# core
# ebpf
# eclecticiq-polylogyx-extension
# extensions
# file-carving
# fleet
# foundation
# general
# golang
# kolide
# linux
# macos
# officehours
# osctrl
# plugins
# process-auditing
# sql
# website
# windows
# zeek
Powered by Linen
Channels
arm-architecture
code-review
core
ebpf
eclecticiq-polylogyx-extension
extensions
file-carving
fleet
foundation
general
golang
kolide
linux
macos
officehours
osctrl
plugins
process-auditing
sql
website
windows
zeek
harveywells
2 years ago
Hi! How do folks manage large
osqueryd.ERROR
and
osqueryd.WARNING
files in
/var/log/osquery
? We recently deployed an log rotate conf for
osqueryd.results.log
but I’m seeing WARNING and ERROR logs files between 5 and 10 MB on some clients.
clong
2 years ago
Is 5-10MB considered too large? If you’re offloading them to a forwarder regularly couldn’t you just update the logrotate conf to rotate earlier?
Join thread in Slack
View count:
5