Log Rotation (logrotate)
Log files grow continuously over time, and without management they will eventually fill up disk space. logrotate is the default log rotation utility on Linux systems, capable of automatically compressing, deleting, and rotating log files. This guide covers logrotate’s configuration structure, writing custom rules, key parameters, and testing methods.
logrotate Overview
Section titled “logrotate Overview”logrotate is automatically executed once daily by a systemd timer (EL 8+) or cron job. It reads rules from configuration files and rotates the specified log files accordingly.
rpm -q logrotatesystemctl status logrotate.timerConfiguration File Structure
Section titled “Configuration File Structure”logrotate configuration consists of two parts:
Global Configuration File
Section titled “Global Configuration File”cat /etc/logrotate.confThe global configuration file /etc/logrotate.conf defines the default rotation policy:
# Rotate weeklyweekly
# Keep 4 rotated logsrotate 4
# Create new empty log files after rotationcreate
# Use date as suffixdateext
# Compress old logscompress
# Include custom configuration directoryinclude /etc/logrotate.dCustom Configuration Directory
Section titled “Custom Configuration Directory”ls /etc/logrotate.d/Each application can place its own rotation configuration file in the /etc/logrotate.d/ directory.
Core Configuration Parameters
Section titled “Core Configuration Parameters”Rotation Frequency
Section titled “Rotation Frequency”| Parameter | Meaning |
|---|---|
daily | Rotate daily |
weekly | Rotate weekly |
monthly | Rotate monthly |
yearly | Rotate yearly |
Rotation Retention
Section titled “Rotation Retention”| Parameter | Meaning |
|---|---|
rotate N | Keep N old log files |
maxage N | Delete logs older than N days |
File Size Control
Section titled “File Size Control”| Parameter | Meaning |
|---|---|
size 100M | Only rotate when log exceeds 100M |
minsize 50M | Only rotate when at least 50M (combined with frequency) |
maxsize 500M | Rotate immediately when exceeding 500M (ignores frequency) |
Compression Options
Section titled “Compression Options”| Parameter | Meaning |
|---|---|
compress | Compress old logs with gzip |
nocompress | Do not compress |
compresscmd bzip2 | Use a specific compression program |
delaycompress | Delay compression by one cycle (useful with copytruncate) |
File Handling
Section titled “File Handling”| Parameter | Meaning |
|---|---|
create 0640 root adm | Create new file after rotation with specified permissions |
copytruncate | Copy then truncate the original file (for apps that cannot reopen logs) |
missingok | Do not error if the log file is missing |
notifempty | Do not rotate if the log file is empty |
sharedscripts | Run scripts only once for all matched files |
Date Suffix
Section titled “Date Suffix”| Parameter | Meaning |
|---|---|
dateext | Use date instead of numeric suffix |
dateformat -%Y%m%d | Custom date format |
dateyesterday | Use yesterday’s date as the suffix |
Creating Custom Rotation Rules
Section titled “Creating Custom Rotation Rules”Nginx Log Rotation
Section titled “Nginx Log Rotation”sudo tee /etc/logrotate.d/nginx << 'EOF'/var/log/nginx/*.log { daily rotate 30 missingok notifempty compress delaycompress dateext sharedscripts postrotate [ -f /var/run/nginx.pid ] && kill -USR1 $(cat /var/run/nginx.pid) endscript}EOFExplanation:
postrotate / endscript— Script executed after rotation; sends USR1 signal to make Nginx reopen log filesdelaycompress— The most recent rotated log is not compressed, making it easier to inspectsharedscripts— Signal is sent only once for multiple log files
Application Log Rotation
Section titled “Application Log Rotation”sudo tee /etc/logrotate.d/myapp << 'EOF'/var/log/myapp/*.log { daily rotate 14 missingok notifempty compress copytruncate size 100M dateext dateformat -%Y%m%d}EOFExplanation:
copytruncate— Copies the log file and then truncates the original, suitable for applications that cannot reopen log files via signalsize 100M— Only rotates when the file exceeds 100M
Tomcat / Java Application Log Rotation
Section titled “Tomcat / Java Application Log Rotation”sudo tee /etc/logrotate.d/tomcat << 'EOF'/opt/tomcat/logs/catalina.out { daily rotate 7 missingok notifempty compress copytruncate maxsize 500M dateext}
/opt/tomcat/logs/catalina.*.log/opt/tomcat/logs/localhost.*.log { daily rotate 7 missingok notifempty compress maxage 30}EOFSystem syslog Rotation
Section titled “System syslog Rotation”cat /etc/logrotate.d/syslogTesting and Debugging
Section titled “Testing and Debugging”Dry Run with -d Flag
Section titled “Dry Run with -d Flag”The -d flag performs a dry run that does not actually modify any files, only showing what would be done:
sudo logrotate -d /etc/logrotate.confsudo logrotate -d /etc/logrotate.d/nginxThe output shows whether each log file needs rotation and what actions would be taken, allowing you to verify that the configuration is correct.
Verbose Output with -v Flag
Section titled “Verbose Output with -v Flag”sudo logrotate -v /etc/logrotate.confForcing Rotation
Section titled “Forcing Rotation”Use the -f flag to force rotation on all log files, ignoring time and size conditions:
sudo logrotate -f /etc/logrotate.confsudo logrotate -f /etc/logrotate.d/nginxCombining Flags
Section titled “Combining Flags”sudo logrotate -vf /etc/logrotate.d/nginxlogrotate State File
Section titled “logrotate State File”logrotate records the last rotation time for each log in a state file:
cat /var/lib/logrotate/logrotate.statusIf you need to reset the rotation state for a particular log, you can edit this file or remove the corresponding line.
Common Troubleshooting
Section titled “Common Troubleshooting”Logs Not Rotating as Expected
Section titled “Logs Not Rotating as Expected”systemctl status logrotate.timerjournalctl -u logrotate --no-pager -n 20sudo logrotate -d /etc/logrotate.d/nginxPermission Issues
Section titled “Permission Issues”ls -la /var/log/nginx/ls -la /etc/logrotate.d/logrotate configuration files must not be group-writable or world-writable, or they will be skipped.
sudo chmod 644 /etc/logrotate.d/nginxChoosing Between copytruncate and postrotate
Section titled “Choosing Between copytruncate and postrotate”- copytruncate — Suitable for programs that do not support signal-based log reopening (e.g., some Java applications), but a small amount of log data may be lost between the copy and truncation
- postrotate + signal — More reliable, suitable for programs that support log file reopening (e.g., Nginx, Apache)
Best Practices
Section titled “Best Practices”- Create separate configuration files for each application — Place them in
/etc/logrotate.d/ - Test with -d after making changes — Confirm the configuration is correct before waiting for actual rotation
- Set appropriate retention counts — Based on disk space and compliance requirements
- Use dateext — Date suffixes are more readable than numeric ones
- Combine with monitoring — Monitor disk usage to ensure rotation is working properly
- Use compress — Saves disk space, especially since text logs have very high compression ratios