The Wanderer (HE12026-07-27):
> That was my own first thought as well, but it only works if you have
> that much control over the applications that will be writing the files

According to the original statement, that is syslog. If there are other
processes logging without going through rsyslog, it makes the issue that
much difficult.

> The only other fallback option that's occurred to me is to mount the
> root filesystem read-only

If the OP wants to avoid unwanted writes on the internal devices, I very
much hope that is the very first thing they did.

Regards,

-- 
  Nicolas George

Reply via email to