AWS Ubuntu 16.04.4 LTS实例日志轮转后写入.log.1而非.log的问题求助
Hey there, no need to apologize at all—this kind of logrotate/rsyslog quirk is super common even for folks who use Linux regularly, so you’re not missing something obvious! Let’s break down what’s happening and fix it step by step.
What’s going on here?
From your description and configs, the core issue is: After logrotate renames the original .log file to .log.1, rsyslog doesn’t automatically switch to writing to the new empty .log file—it keeps writing to the old file (now named .log.1). When you restart rsyslog manually, you force it to recheck the log file paths, so it starts writing to .log again—but that only works until the next rotation because the post-rotation script isn’t triggering the right action.
Looking at your /etc/logrotate.d/rsyslog config, the invoke-rc.d rsyslog rotate command in the postrotate block isn’t properly telling rsyslog to reload its log files on Ubuntu 16.04. We need to use a more reliable method to get rsyslog to recognize the new log file.
Step-by-Step Fix
Since you’re new to Linux, I’ll keep this as simple and clear as possible:
Open the rsyslog logrotate config file
We’ll usenano(a beginner-friendly text editor) to edit the file. Run this command in your terminal:sudo nano /etc/logrotate.d/rsyslogEnter your sudo password when prompted (you won’t see the characters as you type—this is normal!).
Update the postrotate script
There are two separate log blocks in this file (one for/var/log/syslog, and one for the group including/var/log/auth.log). For both blocks, find this section:postrotate invoke-rc.d rsyslog rotate > /dev/null endscriptReplace the line inside the
postrotate/endscriptblock with this:postrotate /usr/bin/pkill -HUP rsyslogd endscriptThe
-HUPsignal is a standard Linux way to tell rsyslog to reload its config and reopen all log files—this will make it switch to the new.logfile right after rotation.Save and exit the editor
In nano:- Press
Ctrl+Oto save the file, then hitEnterto confirm the filename. - Press
Ctrl+Xto close nano.
- Press
Test the fix manually
To make sure this works without waiting for the next scheduled rotation, force logrotate to run immediately for rsyslogs:sudo logrotate -f /etc/logrotate.d/rsyslogVerify the fix works
Check if new log entries are going to.logby running:tail -f /var/log/auth.logDo something that would generate an auth log entry (like running
sudo lsor trying an SSH login), and you should see new lines appear in the output. PressCtrl+Cto stop watching the log.
Why This Works
When logrotate renames .log to .log.1, rsyslog doesn’t automatically know the file was renamed—it keeps writing to the original file descriptor. The -HUP signal tells rsyslog to close all open log files and reopen them using their original paths, so it starts writing to the new empty .log file that logrotate creates during rotation.
Backup Check (If the Fix Still Doesn’t Work)
If you still have issues, double-check that logrotate is creating the new .log file with the right permissions. Add a create line to each log block in /etc/logrotate.d/rsyslog (matching the permissions of your existing log files). For example, the group block including auth.log would look like this:
/var/log/mail.info /var/log/mail.warn /var/log/mail.err /var/log/mail.log /var/log/daemon.log /var/log/kern.log /var/log/auth.log /var/log/user.log /var/log/lpr.log /var/log/cron.log /var/log/debug /var/log/messages { rotate 4 weekly missingok notifempty compress delaycompress sharedscripts create 0640 syslog adm postrotate /usr/bin/pkill -HUP rsyslogd endscript }
This ensures logrotate creates the new .log file with the correct owner and permissions so rsyslog can write to it.
备注:内容来源于stack exchange,提问作者Henrik Koberg

