<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Why doesn't /var/log/messages have the 100 MiB rsyslog trigger?]]></title><description><![CDATA[<p dir="auto">I'm trying to understand the intended design of the XCP-ng logging configuration.</p>
<p dir="auto">XCP-ng uses rsyslog to trigger /etc/cron.daily/logrotate when certain log files reach 100 MiB, so they don't have to wait for the next scheduled daily logrotate run.</p>
<p dir="auto">Looking at /etc/rsyslog.d/xenserver.conf, there are outchannel definitions with a 100 MiB limit for several log files (kern.log, daemon.log, user.log, secure, maillog, cron, xensource.log, etc.).</p>
<p dir="auto">However, /var/log/messages does not appear to have such an outchannel.</p>
<p dir="auto">I understand that /var/log/messages is also part of the traditional CentOS/RHEL syslog configuration, rather than being an XCP-ng-specific log. So I'm wondering where the responsibility for limiting its size is supposed to lie.</p>
<p dir="auto">Is the expectation that the underlying CentOS logging configuration and normal daily logrotate are sufficient for /var/log/messages, while XCP-ng adds the 100 MiB rsyslog trigger only for its own/specific log files?</p>
<p dir="auto">If /var/log/messages can receive a sufficiently high volume of messages, could it theoretically grow large enough to fill the log partition before the next daily logrotate run?</p>
<p dir="auto">If so, would it make sense for XCP-ng to add the same 100 MiB rsyslog trigger for /var/log/messages, or is there a specific reason why this would not be appropriate?</p>
]]></description><link>https://xcp-ng.org/forum/topic/12452/why-doesn-t-var-log-messages-have-the-100-mib-rsyslog-trigger</link><generator>RSS for Node</generator><lastBuildDate>Thu, 03 Sep 2026 11:48:10 GMT</lastBuildDate><atom:link href="https://xcp-ng.org/forum/topic/12452.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 03 Sep 2026 11:17:10 GMT</pubDate><ttl>60</ttl></channel></rss>