Re: the binary logs - true, but the core point that its not text by default is still a (small) issue IMO. Not ideal default behaviour.
Re: the binary logs - true, but the core point that its not text by default is still a (small) issue IMO. Not ideal default behaviour.
The nice thing about its binary log format is that it's organised by fields which are indexed for quicker searching and filtering. It's much easier and faster to analyse these logs than the traditional text-based ones.
Also, having journald authenticate the process that is sending it log entries, and the log sealing capability, are two features that can help guard against log tampering.
I think I am not the only one who is missing negative filters - check the log excluding audit messages.
- It's immediately compressed (without having to wait for a log rotation);
- It automatically rotates when a size limit is reached (no risk of filling the disk with logs);
- IIRC, it's deduplicated (repeated messages use less disk space).
All of these together means logs can be kept for much longer by default.