blog
Table des matières
- 2026:
- 2025:
9 billet(s) pour mars 2026
| Notes SOPS | 2026/03/30 17:47 | Jean-Baptiste |
| Notes conteneurs oras artifact OCI | 2026/03/23 21:13 | Jean-Baptiste |
| Notes podman secret | 2026/03/23 15:10 | Jean-Baptiste |
| Notes ansible podman | 2026/03/23 14:08 | Jean-Baptiste |
| Notes podman volume | 2026/03/23 14:00 | Jean-Baptiste |
| Find list - Trouver des fichiers à partir d'une liste | 2026/03/18 14:32 | Jean-Baptiste |
| AWX inventaire vault | 2026/03/17 18:04 | Jean-Baptiste |
| AWX - Configuration git en local (sans serveur web) | 2026/03/05 16:24 | Jean-Baptiste |
| OpenSMTP | 2026/03/03 16:58 | Jean-Baptiste |
Notes logrotate
Voir :
Voir aussi :
/etc/cron.daily/logrotate
#!/bin/sh /usr/sbin/logrotate /etc/logrotate.conf >/dev/null 2>&1 EXITVALUE=$? if [ $EXITVALUE != 0 ]; then /usr/bin/logger -t logrotate "ALERT exited abnormally with [$EXITVALUE]" fi exit 0
Exemple de conf
/opt/atom/apache-tomcat-*/logs/catalina.out
{
copytruncate
weekly
rotate 52
compress
missingok
size 5M
}
/var/log/cups/*_log {
missingok
notifempty
sharedscripts
}
/var/log/dracut.log {
missingok
notifempty
size 30k
yearly
create 0600 root root
}
/var/log/clamav/freshclam.log {
missingok
notifempty
create 644 clam clam
}
/var/log/httpd/*log {
missingok
notifempty
sharedscripts
delaycompress
postrotate
/sbin/service httpd reload > /dev/null 2>/dev/null || true
endscript
}
/var/log/numad.log {
compress
copytruncate
maxage 60
missingok
rotate 5
size 1M
}
# Rotate OCS Inventory NG agent logs daily, only if not empty
# Save 7 days old logs under compressed mode
/var/log/ocsinventory-agent/*.log {
daily
rotate 7
compress
notifempty
missingok
}
/var/account/pacct {
#prerotate loses accounting records, let's no
# prerotate
# /usr/sbin/accton
# endscript
compress
delaycompress
notifempty
daily
rotate 31
create 0600 root root
postrotate
/usr/sbin/accton /var/account/pacct
endscript
}
/var/log/sssd/*.log {
weekly
missingok
notifempty
sharedscripts
rotate 2
compress
postrotate
/bin/kill -HUP `cat /var/run/sssd.pid 2>/dev/null` 2> /dev/null || true
endscript
}
/var/log/cron
/var/log/maillog
/var/log/messages
/var/log/secure
/var/log/spooler
{
sharedscripts
postrotate
/bin/kill -HUP `cat /var/run/syslogd.pid 2> /dev/null` 2> /dev/null || true
endscript
}
/var/log/yum.log {
missingok
notifempty
size 30k
yearly
create 0600 root root
}
Test
logrotate -df /etc/logrotate.d/plop
Shellshock
Il est possible de vérifier si la version de bash est vulnérable avec la commande :
env VAR='() { 0; }; echo danger' bash -c "echo bonjour"
Cette faille est corrigée si votre système est à jour
blog.txt · Dernière modification : de 127.0.0.1
