3 ms·
Never centralize logging. Log at the leaves and store it there. Push search predicates down to servers running on each leaf when/if needed. Log to sockets alway
by bt848 7y ago
Never centralize logging. Log at the leaves and store it there. Push search predicates down to servers running on each leaf when/if needed. Log to sockets always; your FD can be a regular file if you want but keep the flexibility to change it later.
- viraptor 7y agoThis doesn't work well unless all your servers are custom pets or real hardware. If you have ephemeral instances scaling up/down, you'd lose history this way. Also you'd affect performance of the service, likely when you need it most - when the app is having issues and you're trying to debug it. There may be also limitation around data retention on a single machine. If you're doing distributed containers, lambdas, or other more ephemeral things, you just can't do logging at leaf unfortunately.
- millettjon 7y agoLeaf logging is also susceptible to attackers deleting log files. Central logging is effectively append only from the leaf and thus provides a security benefit.
- weq 7y agoSo the attacker starts DoSing your central log server and you do what?
- bananocurrency 7y agohow is my logging server being attacked from outside my network?