Hi Richard,
The method that i used for a while is storing app logs on my Splunk(it may be any solution). In this way, i can search historically as much as i want. I can create dashboard or analytic reports.
I used Splunk Forwarder to forward logs but you may use any method to do it. (syslog or any agent)
To send logs, you can use below path.
//var/lib/rancher/k3s/agent/containerd/io.containerd.snapshotter.v1.overlayfs/snapshots/*/fs/var/log/rescircuits/app.log------------------------------
Burak Karaduman
------------------------------