You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Ubuntu 16.04.4 LTS实例日志轮转后写入.log.1而非.log的问题求助

AWS Ubuntu 16.04.4 LTS实例日志轮转后写入.log.1而非.log的问题求助

Hey there, no need to apologize at all—this kind of logrotate/rsyslog quirk is super common even for folks who use Linux regularly, so you’re not missing something obvious! Let’s break down what’s happening and fix it step by step.

What’s going on here?

From your description and configs, the core issue is: After logrotate renames the original .log file to .log.1, rsyslog doesn’t automatically switch to writing to the new empty .log file—it keeps writing to the old file (now named .log.1). When you restart rsyslog manually, you force it to recheck the log file paths, so it starts writing to .log again—but that only works until the next rotation because the post-rotation script isn’t triggering the right action.

Looking at your /etc/logrotate.d/rsyslog config, the invoke-rc.d rsyslog rotate command in the postrotate block isn’t properly telling rsyslog to reload its log files on Ubuntu 16.04. We need to use a more reliable method to get rsyslog to recognize the new log file.


Step-by-Step Fix

Since you’re new to Linux, I’ll keep this as simple and clear as possible:

  1. Open the rsyslog logrotate config file
    We’ll use nano (a beginner-friendly text editor) to edit the file. Run this command in your terminal:

    sudo nano /etc/logrotate.d/rsyslog
    

    Enter your sudo password when prompted (you won’t see the characters as you type—this is normal!).

  2. Update the postrotate script
    There are two separate log blocks in this file (one for /var/log/syslog, and one for the group including /var/log/auth.log). For both blocks, find this section:

    postrotate
        invoke-rc.d rsyslog rotate > /dev/null
    endscript
    

    Replace the line inside the postrotate/endscript block with this:

    postrotate
        /usr/bin/pkill -HUP rsyslogd
    endscript
    

    The -HUP signal is a standard Linux way to tell rsyslog to reload its config and reopen all log files—this will make it switch to the new .log file right after rotation.

  3. Save and exit the editor
    In nano:

    • Press Ctrl+O to save the file, then hit Enter to confirm the filename.
    • Press Ctrl+X to close nano.
  4. Test the fix manually
    To make sure this works without waiting for the next scheduled rotation, force logrotate to run immediately for rsyslogs:

    sudo logrotate -f /etc/logrotate.d/rsyslog
    
  5. Verify the fix works
    Check if new log entries are going to .log by running:

    tail -f /var/log/auth.log
    

    Do something that would generate an auth log entry (like running sudo ls or trying an SSH login), and you should see new lines appear in the output. Press Ctrl+C to stop watching the log.


Why This Works

When logrotate renames .log to .log.1, rsyslog doesn’t automatically know the file was renamed—it keeps writing to the original file descriptor. The -HUP signal tells rsyslog to close all open log files and reopen them using their original paths, so it starts writing to the new empty .log file that logrotate creates during rotation.


Backup Check (If the Fix Still Doesn’t Work)

If you still have issues, double-check that logrotate is creating the new .log file with the right permissions. Add a create line to each log block in /etc/logrotate.d/rsyslog (matching the permissions of your existing log files). For example, the group block including auth.log would look like this:

/var/log/mail.info
/var/log/mail.warn
/var/log/mail.err
/var/log/mail.log
/var/log/daemon.log
/var/log/kern.log
/var/log/auth.log
/var/log/user.log
/var/log/lpr.log
/var/log/cron.log
/var/log/debug
/var/log/messages
{
    rotate 4
    weekly
    missingok
    notifempty
    compress
    delaycompress
    sharedscripts
    create 0640 syslog adm
    postrotate
        /usr/bin/pkill -HUP rsyslogd
    endscript
}

This ensures logrotate creates the new .log file with the correct owner and permissions so rsyslog can write to it.


备注:内容来源于stack exchange,提问作者Henrik Koberg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 07:49:52