RestrictAddressFamilies=AF_UNIX
SystemCallFilter=~@clock @cpu-emulation @debug @keyring @module @mount @obsolete @raw-io @reboot @swap
SystemCallArchitectures=native
-ReadWritePaths=/var/lib/systemd/coredump
+StateDirectory=systemd/coredump
RestrictNamespaces=yes
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
SystemCallArchitectures=native
-ReadWritePaths=/var/log/journal/remote
+LogsDirectory=journal/remote
[Install]
Also=systemd-journal-remote.socket
RestrictNamespaces=yes
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
SystemCallArchitectures=native
-ReadWritePaths=/var/lib/systemd/journal-upload
+StateDirectory=systemd/journal-upload
# If there are many split up journal files we need a lot of fds to
# access them all and combine