Prevent forwarding of systemd service logs to syslog without affecting other service logs sent to syslog

Viewed 4802

My computer runs serveral java processes as systemd services.The systemd logs get accumulated in the syslog eventually leading to low disk space . How to re-direct the logs started by systemd services towards /dev/null so that it does not accumulate in syslog.The machine is constantly running out of disk space due to this issue.However , I need to be able to use journalctl to view the systemd service logs. The possible solutions I found were :

1.To modify configurations in /etc/systemd/journald.conf by setting 'ForwardToSyslog=no'

2.Adding StandardOutput=null within the systemd service file itself

However the first solution completely stopped all the logs sent to syslog and solution 2 did not work.I wish to stop forwarding only the log messages from systemd services.

3 Answers

The second option with StandardOutput=null should work. I think what you need is to redirect also STDERR to /dev/null, by adding StandardError=null. Summarize - in your *.service file should be two lines:

[Service]
StandardOutput=null
StandardError=null

Refer SYSTEMD.EXEC(5) man page for more details.

Similarly on a Redhat 7.4 box, running systemd-219-42.el7_4.1.x86_64, I was unable to turn off log redirection with the 'ForwardToSyslog=no' setting in /etc/systemd/journald.conf.

I instead had success with setting 'MaxLevelSyslog=warning' which removed all the INFO and DEBUG level messages that were being forwarded to rsyslog.

You can configure rsyslog to ignore logs from specific application:

# cat /etc/rsyslog.d/mydaemon.conf 
if $programname == 'mydaemon' then {
    stop
}

This will result in:

  1. You will see systemd-generated messages about daemon being started/stopped/reloaded/etc within journal AND syslog.
  2. You will see daemon's-generated messages ONLY in journal (and custom log file written directly by application, if any).
Related