Skip to main content

Jboss is truncating log file contents when it is restarted

In order to avoid truncating server.log file contents when restarting jboss, change jboss-log4j.xml FILE Appender class.

<appender name="FILE" class="org.jboss.logging.appender.RollingFileAppender">

     <errorHandler class="org.jboss.logging.util.OnlyOnceErrorHandler"/>
     <param name="File" value="${jboss.server.log.dir}/server.log"/>
     <param name="Append" value="false"/>
     <param name="MaxFileSize" value="50MB"/>
     <param name="MaxBackupIndex" value="20"/>

     <layout class="org.apache.log4j.PatternLayout">
       <param name="ConversionPattern" value="%d %-5p [%c] %m%n"/>
     </layout>
   </appender>

Set value of the Append parameter to "true"

Comments

  1. I found the service that was filling up the d:\kronos\jboss\bin\stderrwfc.log and shut it down in the log config.

    I'm looking into how to set the service to truncate that log back to zero when I restart the service. At the moment it is set to keep the log file and append on a restart.

    We're close. If anyone know "log4j" configuration over there, that appears to be the key.

    ReplyDelete
  2. If stderrwfc.log is server log file and can be managed via log4j, as far as i know param name="Append" value="false" will do the trick.

    ReplyDelete

Post a Comment

Popular posts from this blog

Find and replace with sed command in Linux

Find and replace feature is always handy. It can turn into a torture when it comes to change or delete a simple constant string in a text file. There is a handy tool in linux for doing these kind of tihngs. Actually sed is not a text editor but it is used outside of the text file to make changes.

Sending Jboss Server Logs to Logstash Using Filebeat with Multiline Support

In addition to sending system logs to logstash, it is possible to add a prospector section to the filebeat.yml for jboss server logs. Sometimes jboss server.log has single events made up from several lines of messages. In such cases Filebeat should be configured for a multiline prospector.
Filebeat takes lines do not start with a date pattern (look at pattern in the multiline section "^[[:digit:]]{4}-[[:digit:]]{2}-[[:digit:]]{2}" and negate section is set to true) and combines them with the previous line that starts with a date pattern.

server.log file excerpt where DatePattern: yyyy-MM-dd-HH and ConversionPattern: %d %-5p [%c] %m%n
Logstash filter: