Set journald log limits on cluster nodes

Set journald size and retention limits on
FactoryTalk® Optix™
High Availability nodes, restart journald, and confirm the merged configuration.
  • Ensure sudo access on each cluster node.
  • Plan journald values for each node based on disk capacity, free space, and required log retention.
IMPORTANT: Use a drop-in file under
/etc/systemd/journald.conf.d
. Do not edit
/etc/systemd/journald.conf
directly.
On High Availability cluster nodes, systemd journald reserves disk space by file system percentage. On larger disks, the default limits can allow more journal data than the node can spare.
Set a drop-in file on each node to cap journal size and retention.
  1. (optional) To review current journal disk use, run
    journalctl --disk-usage
    .
  2. To create the journald drop-in directory, run
    sudo mkdir -p /etc/systemd/journald.conf.d
    .
  3. To create the journald limits file, save the following content in
    /etc/systemd/journald.conf.d/99-journald-log-caps.conf
    .
    These values are starting points. They are not fixed for every system.
    [Journal] SystemMaxUse=1G SystemKeepFree=2G RuntimeMaxUse=256M RuntimeKeepFree=128M MaxRetentionSec=7day
    Recommended starting values
    Setting
    Starting value
    Purpose
    SystemMaxUse
    1G
    Upper bound for persistent journals on disk.
    SystemKeepFree
    2G
    Disk space that journald tries to leave free.
    RuntimeMaxUse
    256M
    Upper bound for volatile journals in
    /run
    .
    RuntimeKeepFree
    128M
    Runtime space that journald tries to leave free.
    MaxRetentionSec
    7day
    Maximum age of journal entries.
  4. To apply the new limits, run
    sudo systemctl restart systemd-journald
    .
  5. To confirm the merged journald configuration, run
    sudo systemd-analyze cat-config systemd/journald.conf
    .
    The command displays the effective settings after systemd merges the base configuration and all drop-in files.
Journald uses the size and retention limits from the drop-in file on the node.
HA Manager sets Kubernetes API audit log limits during installation. You do not need to set these values in journald.
Kubernetes API audit log limits
Setting
Value
Path
/var/log/k3s-audit/audit.log
audit-log-maxage
30
days
audit-log-maxbackup
10
audit-log-maxsize
100
MB
TIP: Worst-case audit log disk use is about 1.1 GB per server node. Include this value in node disk planning, along with journald and application logs.
If different Kubernetes API audit log limits are required, change
audit-log-maxage
,
audit-log-maxbackup
, and
audit-log-maxsize
in
/etc/rancher/k3s/config.yaml.d/20-security.yaml
on each server node, and restart the K3s service on that node.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal