Set journald log limits on cluster nodes
Set journald size and retention limits on
FactoryTalk® Optix™
High Availability nodes, restart journald, and confirm the merged configuration.- Ensure sudo access on each cluster node.
- Plan journald values for each node based on disk capacity, free space, and required log retention.
IMPORTANT:
Use a drop-in file under
/etc/systemd/journald.conf.d
. Do not edit /etc/systemd/journald.conf
directly.On High Availability cluster nodes, systemd journald reserves disk space by file system percentage. On larger disks, the default limits can allow more journal data than the node can spare.
Set a drop-in file on each node to cap journal size and retention.
- (optional) To review current journal disk use, runjournalctl --disk-usage.
- To create the journald drop-in directory, runsudo mkdir -p /etc/systemd/journald.conf.d.
- To create the journald limits file, save the following content in/etc/systemd/journald.conf.d/99-journald-log-caps.conf.These values are starting points. They are not fixed for every system.[Journal] SystemMaxUse=1G SystemKeepFree=2G RuntimeMaxUse=256M RuntimeKeepFree=128M MaxRetentionSec=7dayRecommended starting valuesSettingStarting valuePurposeSystemMaxUse1GUpper bound for persistent journals on disk.SystemKeepFree2GDisk space that journald tries to leave free.RuntimeMaxUse256MUpper bound for volatile journals in/run.RuntimeKeepFree128MRuntime space that journald tries to leave free.MaxRetentionSec7dayMaximum age of journal entries.
- To apply the new limits, runsudo systemctl restart systemd-journald.
- To confirm the merged journald configuration, runsudo systemd-analyze cat-config systemd/journald.conf.The command displays the effective settings after systemd merges the base configuration and all drop-in files.
Journald uses the size and retention limits from the drop-in file on the node.
HA Manager sets Kubernetes API audit log limits during installation. You do not need to set
these values in journald.
Setting | Value |
|---|---|
Path | /var/log/k3s-audit/audit.log |
audit-log-maxage | 30 days |
audit-log-maxbackup | 10 |
audit-log-maxsize | 100 MB |
TIP:
Worst-case audit log disk use is about 1.1 GB per
server node. Include this value in node disk planning, along with journald and application
logs.
If different Kubernetes API audit log limits are required, change
audit-log-maxage
, audit-log-maxbackup
, and audit-log-maxsize
in /etc/rancher/k3s/config.yaml.d/20-security.yaml
on each server node, and restart the K3s service on that node.High Availability
journald
systemd
log retention
cluster nodes
Kubernetes audit logs
Provide Feedback