summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDaniel Micay <danielmicay@gmail.com>2023-02-10 04:48:30 -0500
committerDaniel Micay <danielmicay@gmail.com>2023-02-10 08:04:25 -0500
commitb903dd72ace8e7340b233fdeb81a8841d42fc8d3 (patch)
treec39949c0973c71739faad00ab34e875fa1a8e2d0
parent10652acf13a98ffb2fb7bc40155ac5d98ebfea6b (diff)
switch to improved custom log format
This switches to a fully custom log format instead of using a variant of the standard combined format since we don't use any tools requiring the logs to be a standard format. This provides a cleaner format, allows us to freely add new fields and gets rid of legacy/redundant fields. The redundant timestamp already provided as the syslog timestamp is dropped along with the legacy identd field always set to a dash. This adds the connection serial number for identifying requests coming from the same connection. TLS version is added as a replacement for our previous addition of the URI scheme. This also adds the total request length and total bytes sent to the client instead of only the body bytes sent.
-rw-r--r--nginx/nginx.conf4
1 files changed, 2 insertions, 2 deletions
diff --git a/nginx/nginx.conf b/nginx/nginx.conf
index ad00fd68..201a66a8 100644
--- a/nginx/nginx.conf
+++ b/nginx/nginx.conf
@@ -64,8 +64,8 @@ http {
# maintained by certbot-ocsp-fetcher
ssl_stapling_file ocsp-cache/grapheneos.org.der;
- log_format main '$remote_addr - $remote_user [$time_local] '
- '"$request_method $scheme://$host$request_uri $server_protocol" $status $body_bytes_sent '
+ log_format main '$connection $remote_addr $remote_user $ssl_protocol $server_protocol '
+ '$host "$request_uri" $status $request_length $body_bytes_sent/$bytes_sent '
'"$http_referer" "$http_user_agent"';
access_log syslog:server=unix:/dev/log,nohostname main;
error_log syslog:server=unix:/dev/log,nohostname;