LINUXOR.SK ... open source notes ...

Vault - logrotate.d/vault (audit log)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Audit logging and log shipping

Rotation of the Vault audit log. Besides rotating, it renames the compressed file so that its name carries the node, because the files of all nodes later meet in one bucket.

ItemValue
Path on the host/etc/logrotate.d/vault
Mode0644
Deployed onevery Vault node, with its own node name in the mv line
Shown herenode 1
Result/var/log/vault/vault1-audit-YYYY-MM-DD.log.gz

The file

nginx
/var/log/vault/audit.log {
    notifempty
    missingok
    copytruncate
    dateext
    dateformat %Y-%m-%d.
    extension log
    compress
    nodelaycompress
    lastaction
        mv /var/log/vault/audit.$(date +%Y-%m-%d).log.gz /var/log/vault/vault1-audit-$(date +%Y-%m-%d).log.gz
        find /var/log/vault/ -type f -mtime +14 -delete
    endscript
}

Reading it today

← solutionz