EDR: How to create a symbolic link to move the /var/log/cb data location
book
Article ID: 290912
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Explain how to create a symbolic link in the Linux OS to relocate the log file data for the EDR product to a different location without breaking the product functionality.
Logging should continue to work as expected at new location, but if not, open a Support case with Carbon Black
Log rotation still works correctly, and does rotate the logs and delete old ones (advanced system time and invoked log rotate, confirmed older logs were gone as expected)
CBDiag utility can still pull logs from the symlinked location
The cb-redis and cb-rabbitmq services, which are based on third-party software, are apparently unable to write log files to a symlink, and must be configured to explicitly use the new location (see instructions above). However, their log files can still be accessed using the symlink.