Vault - logrotate.d/vault (audit log)
Vault Solution · Config document · referenced from Audit logging and log shipping
Rotation of the Vault audit log. Besides rotating, it renames the compressed file so that its name carries the node, because the files of all nodes later meet in one bucket.
| Item | Value |
|---|---|
| Path on the host | /etc/logrotate.d/vault |
| Mode | 0644 |
| Deployed on | every Vault node, with its own node name in the mv line |
| Shown here | node 1 |
| Result | /var/log/vault/vault1-audit-YYYY-MM-DD.log.gz |
The file
/var/log/vault/audit.log {
notifempty
missingok
copytruncate
dateext
dateformat %Y-%m-%d.
extension log
compress
nodelaycompress
lastaction
mv /var/log/vault/audit.$(date +%Y-%m-%d).log.gz /var/log/vault/vault1-audit-$(date +%Y-%m-%d).log.gz
find /var/log/vault/ -type f -mtime +14 -delete
endscript
}Reading it today
copytruncatecan lose audit entries. The file is copied and then truncated while Vault keeps writing; whatever is written between the two steps is gone. Vault reopens its audit file onSIGHUP, so apostrotateblock withsystemctl kill -s HUP vaultand nocopytruncateis the documented way. See the file audit device.find … -mtime +14 -deleteruns on the whole directory. It also deletes the compressed files that have not reached object storage yet if the upload has been failing for two weeks.