When we have a universal forwarder installed on a VM server (hard drive is 40gb). When the service went down yesterday the logs started to queue up on the server as expected but it took so long to get the service back up and running that we ran in to issues where the hard drive was filled up. How can i set a hard stop for the size of logs the universal forwarder can queue up before it starts to purge the older logs?
use case:
if service fails, queue logs up to 10gb (or 25% of free space or something static like that), once that limit is reached, purge old logs to make room for new logs until service is restored.
Any help would be greatly appreciated! Thanks!
... View more