Files
Ansible/playbooks/maintenance_backup_event_log.yml
T
admin_rb d095887d2e snapshot
2026-09-15 21:33:10 +02:00

75 lines
2.3 KiB
YAML

---
- name: "Maintenance | Backup system logs"
hosts: all
gather_facts: true
vars:
windows_event_log_backup_dir: 'C:\\Windows\\Temp\\EventLogBackup'
windows_event_logs_to_backup:
- Application
- System
- Security
linux_log_backup_dir: /var/backups/system-logs
linux_journal_since: "-24h"
tasks:
- name: "Windows | Ensure event log backup directory exists"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_file:
path: "{{ windows_event_log_backup_dir }}"
state: directory
- name: "Windows | Export event logs"
when: ansible_facts['os_family'] == 'Windows'
ansible.windows.win_command: >-
wevtutil epl {{ item }} "{{ windows_event_log_backup_dir }}\\{{ item }}.evtx" /ow:true
loop: "{{ windows_event_logs_to_backup }}"
changed_when: true
- name: "Linux | Ensure system log backup directory exists"
when: ansible_facts['os_family'] != 'Windows'
become: true
ansible.builtin.file:
path: "{{ linux_log_backup_dir }}"
state: directory
owner: root
group: root
mode: "0750"
- name: "Linux | Check whether systemd journal is available"
when: ansible_facts['os_family'] != 'Windows'
ansible.builtin.command:
cmd: journalctl --version
register: journalctl_available
changed_when: false
failed_when: false
- name: "Linux | Export systemd journal"
when:
- ansible_facts['os_family'] != 'Windows'
- journalctl_available.rc == 0
become: true
ansible.builtin.shell: >-
journalctl --since {{ linux_journal_since | quote }} --no-pager
> {{ (linux_log_backup_dir ~ '/journal.log') | quote }}
args:
executable: /bin/sh
changed_when: true
- name: "Linux | Backup traditional system logs"
when:
- ansible_facts['os_family'] != 'Windows'
- journalctl_available.rc != 0
become: true
ansible.builtin.shell: |
set -e
for file in /var/log/syslog /var/log/messages /var/log/auth.log /var/log/secure; do
if [ -f "$file" ]; then
cp -p "$file" "{{ linux_log_backup_dir }}/$(basename "$file")"
fi
done
args:
executable: /bin/sh
changed_when: true