Rain Wiki · Linux

logrotate

What logrotate does, how its configuration in /etc/logrotate.conf and /etc/logrotate.d works, and how to test a rule safely.

Linux · Rain Wiki

logrotate is a Linux utility that rotates, compresses and removes log files so they do not fill the disk. It is usually run once a day by a systemd timer or cron job and reads /etc/logrotate.conf plus the per-package rules in /etc/logrotate.d/.

A typical rule

A rule names one or more log files and directives such as daily or weekly (how often), rotate 7 (how many old files to keep), compress (gzip old files), missingok (no error if the file is absent), notifempty (skip empty logs) and postrotate ... endscript (a command to run after rotation, for example to reopen the log).

copytruncate

Some programs keep writing to the same open file. copytruncate copies the log and then truncates the original instead of moving it, so the program keeps its file handle; a few lines written during the copy can be lost.

Testing

'logrotate -d /etc/logrotate.conf' runs in debug mode and only prints what would happen. '-f' forces a rotation even if it is not due.

How to add and test a rule

  1. Create /etc/logrotate.d/myapp with the log path and directives, for example weekly, rotate 4, compress, missingok, notifempty.
  2. Dry run: sudo logrotate -d /etc/logrotate.d/myapp
  3. If the output looks right, force one rotation: sudo logrotate -f /etc/logrotate.d/myapp
  4. Check the result: ls -l the log directory.

Cautions

  • A wrong path pattern can rotate or delete logs of other programs.
  • Logs managed by the systemd journal are limited in journald.conf, not by logrotate.

Sources

Last updated: 2026-10-08

Related articles