Skip to content

Log Rotation (logrotate)

Log files grow continuously over time, and without management they will eventually fill up disk space. logrotate is the default log rotation utility on Linux systems, capable of automatically compressing, deleting, and rotating log files. This guide covers logrotate’s configuration structure, writing custom rules, key parameters, and testing methods.

logrotate is automatically executed once daily by a systemd timer (EL 8+) or cron job. It reads rules from configuration files and rotates the specified log files accordingly.

Confirm logrotate is installed
rpm -q logrotate
Check the logrotate timer status (EL 8+)
systemctl status logrotate.timer

logrotate configuration consists of two parts:

View the global configuration
cat /etc/logrotate.conf

The global configuration file /etc/logrotate.conf defines the default rotation policy:

/etc/logrotate.conf default contents
# Rotate weekly
weekly
# Keep 4 rotated logs
rotate 4
# Create new empty log files after rotation
create
# Use date as suffix
dateext
# Compress old logs
compress
# Include custom configuration directory
include /etc/logrotate.d
List existing rotation rules
ls /etc/logrotate.d/

Each application can place its own rotation configuration file in the /etc/logrotate.d/ directory.

ParameterMeaning
dailyRotate daily
weeklyRotate weekly
monthlyRotate monthly
yearlyRotate yearly
ParameterMeaning
rotate NKeep N old log files
maxage NDelete logs older than N days
ParameterMeaning
size 100MOnly rotate when log exceeds 100M
minsize 50MOnly rotate when at least 50M (combined with frequency)
maxsize 500MRotate immediately when exceeding 500M (ignores frequency)
ParameterMeaning
compressCompress old logs with gzip
nocompressDo not compress
compresscmd bzip2Use a specific compression program
delaycompressDelay compression by one cycle (useful with copytruncate)
ParameterMeaning
create 0640 root admCreate new file after rotation with specified permissions
copytruncateCopy then truncate the original file (for apps that cannot reopen logs)
missingokDo not error if the log file is missing
notifemptyDo not rotate if the log file is empty
sharedscriptsRun scripts only once for all matched files
ParameterMeaning
dateextUse date instead of numeric suffix
dateformat -%Y%m%dCustom date format
dateyesterdayUse yesterday’s date as the suffix
Create Nginx log rotation configuration
sudo tee /etc/logrotate.d/nginx << 'EOF'
/var/log/nginx/*.log {
daily
rotate 30
missingok
notifempty
compress
delaycompress
dateext
sharedscripts
postrotate
[ -f /var/run/nginx.pid ] && kill -USR1 $(cat /var/run/nginx.pid)
endscript
}
EOF

Explanation:

  • postrotate / endscript — Script executed after rotation; sends USR1 signal to make Nginx reopen log files
  • delaycompress — The most recent rotated log is not compressed, making it easier to inspect
  • sharedscripts — Signal is sent only once for multiple log files
Create custom application log rotation configuration
sudo tee /etc/logrotate.d/myapp << 'EOF'
/var/log/myapp/*.log {
daily
rotate 14
missingok
notifempty
compress
copytruncate
size 100M
dateext
dateformat -%Y%m%d
}
EOF

Explanation:

  • copytruncate — Copies the log file and then truncates the original, suitable for applications that cannot reopen log files via signal
  • size 100M — Only rotates when the file exceeds 100M
Create Tomcat log rotation configuration
sudo tee /etc/logrotate.d/tomcat << 'EOF'
/opt/tomcat/logs/catalina.out {
daily
rotate 7
missingok
notifempty
compress
copytruncate
maxsize 500M
dateext
}
/opt/tomcat/logs/catalina.*.log
/opt/tomcat/logs/localhost.*.log {
daily
rotate 7
missingok
notifempty
compress
maxage 30
}
EOF
View the default syslog rotation configuration
cat /etc/logrotate.d/syslog

The -d flag performs a dry run that does not actually modify any files, only showing what would be done:

Test all rotation rules (dry run)
sudo logrotate -d /etc/logrotate.conf
Test a single configuration file
sudo logrotate -d /etc/logrotate.d/nginx

The output shows whether each log file needs rotation and what actions would be taken, allowing you to verify that the configuration is correct.

Run rotation with verbose output
sudo logrotate -v /etc/logrotate.conf

Use the -f flag to force rotation on all log files, ignoring time and size conditions:

Force rotation of all logs
sudo logrotate -f /etc/logrotate.conf
Force rotation of a single configuration
sudo logrotate -f /etc/logrotate.d/nginx
Force rotation with verbose output
sudo logrotate -vf /etc/logrotate.d/nginx

logrotate records the last rotation time for each log in a state file:

View the logrotate state file
cat /var/lib/logrotate/logrotate.status

If you need to reset the rotation state for a particular log, you can edit this file or remove the corresponding line.

Check if the logrotate timer is functioning
systemctl status logrotate.timer
journalctl -u logrotate --no-pager -n 20
Check configuration file syntax
sudo logrotate -d /etc/logrotate.d/nginx
Check log file permissions
ls -la /var/log/nginx/
Check logrotate configuration file permissions
ls -la /etc/logrotate.d/

logrotate configuration files must not be group-writable or world-writable, or they will be skipped.

Fix configuration file permissions
sudo chmod 644 /etc/logrotate.d/nginx

Choosing Between copytruncate and postrotate

Section titled “Choosing Between copytruncate and postrotate”
  • copytruncate — Suitable for programs that do not support signal-based log reopening (e.g., some Java applications), but a small amount of log data may be lost between the copy and truncation
  • postrotate + signal — More reliable, suitable for programs that support log file reopening (e.g., Nginx, Apache)
  1. Create separate configuration files for each application — Place them in /etc/logrotate.d/
  2. Test with -d after making changes — Confirm the configuration is correct before waiting for actual rotation
  3. Set appropriate retention counts — Based on disk space and compliance requirements
  4. Use dateext — Date suffixes are more readable than numeric ones
  5. Combine with monitoring — Monitor disk usage to ensure rotation is working properly
  6. Use compress — Saves disk space, especially since text logs have very high compression ratios