1- Stopper le service rsyslog:
root@server:~# /etc/init.d/rsyslog stop
Stopping enhanced syslogd: rsyslogd.
2- Faire un mount bind dans /etc/fstab vers le nouveau répertoire ou les futurs logs doivent aller:
vi /etc/fstab
/var/log /media/f51e60ec-855c-48a4-ab7a-dd98a788a0fb/var/log none bind
3- Bouger tous les logs existants vers le repertoire cible:
root@server:/media/f51e60ec-855c-48a4-ab7a-dd98a788a0fb# mv /var/log/* /media/f51e60ec-855c-48a4-ab7a-dd98a788a0fb/var/log/
root@server:~# mount -a
root@server:~# df -h
Sys. fich. Taille Util. Dispo Uti% Monté sur
rootfs 7,0G 1,4G 5,3G 21% /
udev 10M 0 10M 0% /dev
tmpfs 385M 288K 384M 1% /run
/dev/disk/by-uuid/7e8362e3-40be-4ba1-b14d-7e308f6e313f 7,0G 1,4G 5,3G 21% /
tmpfs 5,0M 0 5,0M 0% /run/lock
tmpfs 841M 0 841M 0% /run/shm
tmpfs 1,9G 0 1,9G 0% /tmp
/dev/md127 5,5T 1,2T 4,3T 22% /media/f51e60ec-855c-48a4-ab7a-dd98a788a0fb
/dev/disk/by-uuid/7e8362e3-40be-4ba1-b14d-7e308f6e313f 7,0G 1,4G 5,3G 21% /media/f51e60ec-855c-48a4-ab7a-dd98a788a0fb/var/log
4- Redemarrer le service rsyslog:
root@server:~# /etc/init.d/rsyslog start
Starting enhanced syslogd: rsyslogd.
root@server:~# cd /media/f51e60ec-855c-48a4-ab7a-dd98a788a0fb/var/log/
root@server:/media/f51e60ec-855c-48a4-ab7a-dd98a788a0fb/var/log# ls -ltra
total 40
drwxr-xr-x 3 root root 4096 nov. 10 20:46 ..
-rw-r—– 1 root adm 0 nov. 13 13:59 user.log
-rw-r—– 1 root adm 0 nov. 13 13:59 smartd.log
drwxr-xr-x 2 root root 4096 nov. 13 13:59 samba
-rw-r—– 1 root adm 0 nov. 13 13:59 rsyncd.log
drwxr-xr-x 2 root root 4096 nov. 13 13:59 proftpd
-rw-r—– 1 root adm 0 nov. 13 13:59 mail.warn
-rw-r—– 1 root adm 0 nov. 13 13:59 mail.log
-rw-r—– 1 root adm 0 nov. 13 13:59 mail.info
-rw-r—– 1 root adm 0 nov. 13 13:59 mail.err
-rw-r—– 1 root adm 0 nov. 13 13:59 lpr.log
-rw-r—– 1 root adm 0 nov. 13 13:59 auth.log
drwxr-xr-x 2 root root 4096 nov. 13 13:59 news
drwxr-xr-x 5 root root 4096 nov. 13 13:59 .
-rw-r—– 1 root adm 353 nov. 13 13:59 debug
-rw-r—– 1 root adm 353 nov. 13 13:59 daemon.log
-rw-r—– 1 root adm 777 nov. 13 14:00 syslog
-rw-r—– 1 root adm 424 nov. 13 14:00 messages
-rw-r—– 1 root adm 158 nov. 13 14:00 kern.log