▲
14
Nginx access logs are 95% of my ingest, what can I safely drop?
Mostly static assets and health checks. Nervous about dropping the one thing I later need.
Mostly static assets and health checks. Nervous about dropping the one thing I later need.
Safe: health checks from your own load balancer, 200 and 304 for images, css and js, your own monitoring.
Not safe: anything 4xx or 5xx, anything POST regardless of status, anything touching an admin path.
The subtle one is that dropping all static 200s also loses the evidence somebody downloaded a file they should not have. If you have files behind auth, keep 200s for those paths.