Developer Finds 24-Month Audit Archive Was Silently Consuming Server Resources Daily
A developer managing eight Ubuntu 24.04 servers discovered that an audit logging setup, built to comply with Israel's 24-month data retention regulations, had been generating hundreds of megabytes of unexpected log data daily. The problem surfaced on September 6 when a disk alert showed one server at 75% capacity, with auth.log ballooning to 763 MB in just five days. The root cause was traced to auditd's syslog plugin, enabled on August 31, which routed audit events through rsyslog into auth.log, effectively duplicating log data across the fleet. On the busiest servers, audit-related entries accounted for up to 99.7% of log growth, driven largely by database file operations and application deployments triggering thousands of audit events per run. A control server where the plugin had been disabled since September 8 showed no abnormal growth, confirming the syslog plugin as the culprit.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in