I got a notice from a backup system (rsnapshot) today that it's storage volume was full. A closer look reveals some older snapshots where faillog
, tallylog
and lastlog
are bigger than the actual filesystem they are on (/var
is a 6G partition).
-rw-r--r-- 3 root root 65G Feb 11 08:33 faillog
-rw------- 3 root root 129G Feb 11 08:33 tallylog
-rw-rw-r-- 2 root utmp 585G Feb 11 08:57 lastlog
Redhat says this is normal. Any way to limit the size on these? Can they be safely rotated every few hours?