Skip to content

Configure SEAL Logrotate


Default Behavior

On Linux, SEAL Logrotate provides a configuration for the logrotate system program of the operating system. SEAL Logrotate does not contain its own program.

During the installation, the /etc/logrotate.d/plossys configuration file is created. logrotate evaluates the file on each run. It rotates and deletes the log files of SEAL Systems in the /var/log/seal/ log directory.

By default, /etc/logrotate.d/plossys has the following content:

/var/log/seal/*.log {
  compress
  copytruncate
  daily
  dateext
  dateformat .%Y-%m-%d
  missingok
  notifempty
  rotate 7
  su seal seal
}

The directives have the following meaning:

  • /var/log/seal/*.log: Only files with the .log extension located directly in /var/log/seal/ are processed. Files in subdirectories are not affected.
  • daily: The log files are rotated once a day.
  • rotate 7: 7 rotated log files are kept per log file. Older ones are deleted. With daily rotation, the log files of the last 7 days are kept.
  • compress: Rotated log files are compressed with gzip.
  • dateext and dateformat .%Y-%m-%d: The date is appended to the name of rotated log files, for example <name>.log.2026-09-29.gz.
  • copytruncate: The current log file is copied and then emptied. The services continue writing into the same file. They do not need to be restarted.
  • missingok: Missing log files do not cause an error.
  • notifempty: Empty log files are not rotated.
  • su seal seal: The rotation is done as user seal and group seal.

Literature - logrotate

For more information about the directives, refer to the manual page of logrotate with man logrotate.


Time of the Execution

The operating system defines when logrotate runs, not SEAL Logrotate. Depending on the distribution and version, either a systemd timer or a daily cron job starts logrotate.

To find out when logrotate runs, proceed as follows:

  1. Check whether a systemd timer is used and when it runs next:

    systemctl list-timers logrotate.timer
    
  2. If there is no timer, /etc/cron.daily/logrotate starts logrotate. The time of the daily cron jobs is configured in /etc/anacrontab or /etc/crontab.

Hint - other configurations

Changing the time of the execution affects all logrotate configurations on the server, not only the configuration of SEAL Logrotate.


Adjust the Configuration

Adjust the configuration if the log files have to be kept longer or have to be rotated at another interval.

Prerequisites:

  • You have root rights on the server.

Steps:

  1. Edit /etc/logrotate.d/plossys as root. For example, to keep the log files of the last 14 days, change the rotate directive:

    rotate 14
    

    Caution - file permissions

    The file must belong to root. Only root may have write permissions. The permissions set during the installation are 644. Otherwise, logrotate ignores the file.

  2. Check the configuration without rotating any files:

    sudo logrotate -d /etc/logrotate.d/plossys
    

The changes become effective with the next run of logrotate. No restart is required.

Validation:

  • logrotate -d lists the log files in /var/log/seal/ and reports no errors.
  • To rotate the log files immediately, independent of the schedule, execute:

    sudo logrotate -f /etc/logrotate.d/plossys
    

    Afterwards, /var/log/seal/ contains rotated log files with the current date in the file name.



Back to top