Forum
14

Nginx access logs are 95% of my ingest, what can I safely drop?

asked by cclondon 19 days ago

Mostly static assets and health checks. Nervous about dropping the one thing I later need.

2 answers

Sign in to answer.
vivida (David) 13 points 19 days ago

Safe: health checks from your own load balancer, 200 and 304 for images, css and js, your own monitoring.

Not safe: anything 4xx or 5xx, anything POST regardless of status, anything touching an admin path.

The subtle one is that dropping all static 200s also loses the evidence somebody downloaded a file they should not have. If you have files behind auth, keep 200s for those paths.

shadepl 9 points 19 days ago

health check endpoints alone were 40% of ours. one line in the nginx config

Guidelines Newest Search Back to Trunc