The Wanderer (HE12026-07-27): > That was my own first thought as well, but it only works if you have > that much control over the applications that will be writing the files
According to the original statement, that is syslog. If there are other processes logging without going through rsyslog, it makes the issue that much difficult. > The only other fallback option that's occurred to me is to mount the > root filesystem read-only If the OP wants to avoid unwanted writes on the internal devices, I very much hope that is the very first thing they did. Regards, -- Nicolas George

