What logrotate does, how its configuration in /etc/logrotate.conf and /etc/logrotate.d works, and how to test a rule safely.
logrotate is a Linux utility that rotates, compresses and removes log files so they do not fill the disk. It is usually run once a day by a systemd timer or cron job and reads /etc/logrotate.conf plus the per-package rules in /etc/logrotate.d/.
A rule names one or more log files and directives such as daily or weekly (how often), rotate 7 (how many old files to keep), compress (gzip old files), missingok (no error if the file is absent), notifempty (skip empty logs) and postrotate ... endscript (a command to run after rotation, for example to reopen the log).
Some programs keep writing to the same open file. copytruncate copies the log and then truncates the original instead of moving it, so the program keeps its file handle; a few lines written during the copy can be lost.
'logrotate -d /etc/logrotate.conf' runs in debug mode and only prints what would happen. '-f' forces a rotation even if it is not due.
/etc/logrotate.d/myapp with the log path and directives, for example weekly, rotate 4, compress, missingok, notifempty.sudo logrotate -d /etc/logrotate.d/myappsudo logrotate -f /etc/logrotate.d/myappLast updated: 2026-10-08
How to read logs with journalctl, check how much space the journal uses and shrink it safely with --vacuum options.
How to find what fills a Linux disk with du and the interactive ncdu, with options that stay on one file system.
How cron runs scheduled jobs, the five crontab time fields, where system cron files live and how systemd timers compare.