Configure SEAL Logrotate¶
Default Behavior¶
On Linux, SEAL Logrotate provides a configuration for the logrotate system program of the operating system. SEAL Logrotate does not contain its own program.
During the installation, the /etc/logrotate.d/plossys configuration file is created. logrotate evaluates the file on each run. It rotates and deletes the log files of SEAL Systems in the /var/log/seal/ log directory.
By default, /etc/logrotate.d/plossys has the following content:
/var/log/seal/*.log {
compress
copytruncate
daily
dateext
dateformat .%Y-%m-%d
missingok
notifempty
rotate 7
su seal seal
}
The directives have the following meaning:
/var/log/seal/*.log: Only files with the.logextension located directly in/var/log/seal/are processed. Files in subdirectories are not affected.daily: The log files are rotated once a day.rotate 7: 7 rotated log files are kept per log file. Older ones are deleted. With daily rotation, the log files of the last 7 days are kept.compress: Rotated log files are compressed with gzip.dateextanddateformat .%Y-%m-%d: The date is appended to the name of rotated log files, for example<name>.log.2026-09-29.gz.copytruncate: The current log file is copied and then emptied. The services continue writing into the same file. They do not need to be restarted.missingok: Missing log files do not cause an error.notifempty: Empty log files are not rotated.su seal seal: The rotation is done as usersealand groupseal.
Literature - logrotate
For more information about the directives, refer to the manual page of logrotate with man logrotate.
Time of the Execution¶
The operating system defines when logrotate runs, not SEAL Logrotate. Depending on the distribution and version, either a systemd timer or a daily cron job starts logrotate.
To find out when logrotate runs, proceed as follows:
-
Check whether a systemd timer is used and when it runs next:
systemctl list-timers logrotate.timer -
If there is no timer,
/etc/cron.daily/logrotatestartslogrotate. The time of the daily cron jobs is configured in/etc/anacrontabor/etc/crontab.
Hint - other configurations
Changing the time of the execution affects all logrotate configurations on the server, not only the configuration of SEAL Logrotate.
Adjust the Configuration¶
Adjust the configuration if the log files have to be kept longer or have to be rotated at another interval.
Prerequisites:
- You have
rootrights on the server.
Steps:
-
Edit
/etc/logrotate.d/plossysasroot. For example, to keep the log files of the last 14 days, change therotatedirective:rotate 14Caution - file permissions
The file must belong to
root. Onlyrootmay have write permissions. The permissions set during the installation are644. Otherwise,logrotateignores the file. -
Check the configuration without rotating any files:
sudo logrotate -d /etc/logrotate.d/plossys
The changes become effective with the next run of logrotate. No restart is required.
Validation:
logrotate -dlists the log files in/var/log/seal/and reports no errors.-
To rotate the log files immediately, independent of the schedule, execute:
sudo logrotate -f /etc/logrotate.d/plossysAfterwards,
/var/log/seal/contains rotated log files with the current date in the file name.