How to rotate Apache access logs running on Windows 2000 server.
First off I need to give thanks to Simon Greenhill for finding this post which I used in working / editing my apache httpd.conf files for the following project. This was orginally posted on http://forums.devshed.com. I also used the following link as well>>http://www.ucc.ac.uk/cfms/is/webmaster/cronolog.cfm.
NOW,, ON WITH THE FUN..
==========================================================
My environment :
Web server Windows 2000 server with SP4 installed.
Apache 1.3.31 (Win32)
==========================================================
Anyway when parsing the log files the other day I noticed that my access.log file well over 1 gig in size and growing. And since I am running apache on windows there wasnt any clear way to get past what apache was continuing to write to this, until I started googling the "net". As mentioned above I do need to give "props" to the individuals who worked on this prior to myself.
Anyway this is what I did to resolve my large file issue and to have daily access.log files created.
1.) Download the Win32 version of cronolog.exe program from their website which in my case was 1.6.1 for Win32. I created a folder within my C: called cronolog>> ex. C:\cronolog >> I then unzipped this program and made sure that all files and folders were copied back up one level to the C:\cronolog and not within the cronolog-1.6.1.win32-bin directory which was created when unzipping the file. (sidenote: I am not sure whether this step is totally necessary, but I did this anyway and worked perfectly, you can test within the next level down if you like.)
Wait a minute !!! what the hell is cronolog ??????
From their website:
Cronolog is a simple filter program that reads log file entries from a standard input and writes each entry to the output file specified by a filename template and the current date and time. When the expanded filename changes, the current file is closed and a new one is opened, cronolog is intended to be used in conjunction with a Web server like Apache to split access logs into a daily or monthly log file.
2.) I then created a folder "weblogs" (without the ") in my E:\drive . I have a C:\ for the OS and a E: \ where Apache is installed.
3.) So now I have C:\cronolog and E:\weblogs.
4.) Now time to edit the httpd.conf file>> Start>>Prgrams>>Apache HTTP Server>>Configure Apache Server>>Edit the Apache httpd.conf Configuration File
5.) Once clicking on this your apache httpd.conf file should open up in Notepad.
6.) I then scrolled down to the CustomLog logs/access.log common entry and simply commented this out, by placing a "#" in front of the entry so it looked like the following:
#CustomLog logs/access.log common
7.) Then scroll down a few more lines until you see the following:
#CustomLog logs/access.log combined>> I left this entry commented out and created my own file right below it >> my entry is EXACTLY as show:
CustomLog "|c:/cronolog/cronolog.exe e:/weblogs/access%Y%m%d.log" combined
WHOA,, what is all that, well, let me tell you before the grey matter turns to mush....
This is simpy stating that the first character in the brackets | tells apache that this is a piped rotation, meaning that no threads are lost i.e. people can browse as normal while it rotates and the logs will not miss recording any data. Then next bit tells the apache where cronolog lives and needs to be executed from that directory. The above will generate something like access20052705.log.
8.) After you have made these changes to your httpd.conf file make sure to save changes and you will note that I did not delete anything, merely commented out and added too...
9.) Then I simply stopped and restarted the Apache service from the Start>>Programs>>Apache HTTP Server>>Control Apache Server>> stop and then start.
10.) For testing purposes I actually made changes to the CustomLog and added %H%M for it to log down to hours and minutes >> I then opened the web site and kept surfing through the different links and refreshing the page itself. I then checked in the E:\weblogs and sure enough there were access.log files being writting every minute.
I then re-edited the httpd.conf file as mentioned earlier and took off the %H%M, saved the file and stopped/started the apache services once again and now I have access.logs being written to daily and I can now delete the original access.log file.
Well, thats my story and I am sticking to it!!! I hope someone else finds this info useful.....
biz
NOW,, ON WITH THE FUN..
==========================================================
My environment :
Web server Windows 2000 server with SP4 installed.
Apache 1.3.31 (Win32)
==========================================================
Anyway when parsing the log files the other day I noticed that my access.log file well over 1 gig in size and growing. And since I am running apache on windows there wasnt any clear way to get past what apache was continuing to write to this, until I started googling the "net". As mentioned above I do need to give "props" to the individuals who worked on this prior to myself.
Anyway this is what I did to resolve my large file issue and to have daily access.log files created.
1.) Download the Win32 version of cronolog.exe program from their website which in my case was 1.6.1 for Win32. I created a folder within my C: called cronolog>> ex. C:\cronolog >> I then unzipped this program and made sure that all files and folders were copied back up one level to the C:\cronolog and not within the cronolog-1.6.1.win32-bin directory which was created when unzipping the file. (sidenote: I am not sure whether this step is totally necessary, but I did this anyway and worked perfectly, you can test within the next level down if you like.)
Wait a minute !!! what the hell is cronolog ??????
From their website:
Cronolog is a simple filter program that reads log file entries from a standard input and writes each entry to the output file specified by a filename template and the current date and time. When the expanded filename changes, the current file is closed and a new one is opened, cronolog is intended to be used in conjunction with a Web server like Apache to split access logs into a daily or monthly log file.
2.) I then created a folder "weblogs" (without the ") in my E:\drive . I have a C:\ for the OS and a E: \ where Apache is installed.
3.) So now I have C:\cronolog and E:\weblogs.
4.) Now time to edit the httpd.conf file>> Start>>Prgrams>>Apache HTTP Server>>Configure Apache Server>>Edit the Apache httpd.conf Configuration File
5.) Once clicking on this your apache httpd.conf file should open up in Notepad.
6.) I then scrolled down to the CustomLog logs/access.log common entry and simply commented this out, by placing a "#" in front of the entry so it looked like the following:
#CustomLog logs/access.log common
7.) Then scroll down a few more lines until you see the following:
#CustomLog logs/access.log combined>> I left this entry commented out and created my own file right below it >> my entry is EXACTLY as show:
CustomLog "|c:/cronolog/cronolog.exe e:/weblogs/access%Y%m%d.log" combined
WHOA,, what is all that, well, let me tell you before the grey matter turns to mush....
This is simpy stating that the first character in the brackets | tells apache that this is a piped rotation, meaning that no threads are lost i.e. people can browse as normal while it rotates and the logs will not miss recording any data. Then next bit tells the apache where cronolog lives and needs to be executed from that directory. The above will generate something like access20052705.log.
8.) After you have made these changes to your httpd.conf file make sure to save changes and you will note that I did not delete anything, merely commented out and added too...
9.) Then I simply stopped and restarted the Apache service from the Start>>Programs>>Apache HTTP Server>>Control Apache Server>> stop and then start.
10.) For testing purposes I actually made changes to the CustomLog and added %H%M for it to log down to hours and minutes >> I then opened the web site and kept surfing through the different links and refreshing the page itself. I then checked in the E:\weblogs and sure enough there were access.log files being writting every minute.
I then re-edited the httpd.conf file as mentioned earlier and took off the %H%M, saved the file and stopped/started the apache services once again and now I have access.logs being written to daily and I can now delete the original access.log file.
Well, thats my story and I am sticking to it!!! I hope someone else finds this info useful.....
biz
0 Comments:
Post a Comment
<< Home