# Logrotate - Logs not rotating

**URL:** <https://forum.suricata.io/t/logrotate-logs-not-rotating/2200>\
**Category:** Help\
**Created:** [February 7, 2022, 11:21pm UTC](https://forum.suricata.io/t/logrotate-logs-not-rotating/2200 "2022-02-07T23:21:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cadbane](https://avatars.discourse-cdn.com/v4/letter/c/59ef9b/32.png) [@cadbane](https://forum.suricata.io/u/cadbane)\
**Post date:** [February 7, 2022, 11:21pm UTC](https://forum.suricata.io/t/logrotate-logs-not-rotating/2200/1 "2022-02-07T23:21:31Z")

</div>

Hello Forum:

I have a perplexing problem with rotating logs but I’m sure there is a simple fix. Unfortunately, the simple fix has eluded me. Although there are similar postings that are similar to the issue I am experiencing, none of the postings are exactly the same.

Problem:  
The eve(thread number).json (ie: eve.71.json) and other Suricata log files do not get rotated as expected (hourly or daily, depending on where I’ve placed ‘Logrotate’ ie, /etc/cron.daily or cron.hourly). If I perform (logrotate -f /etc/logrotate.d/surcata), the eve.json DOES rotate to a new filename (example: eve.json-20220101) but Suricata will continue updating the newly rotated log. The new eve.json file remains at zero bytes and never grows but the Suricata process continues to run… Thereafter, hourly or daily rotation continues to NOT function as expected.

Log file rotation of all other file system logs appear to be rotating as expected which makes me believe the problem is related to Suricata or possbly Napatech.

Any insights or suggestions to resolve this problem?  
Thanks!

Background:  
Suricata 6.0.4 was but built for support of Napatech SmartNic (12.7) on Ubuntu 20.04.3.

Contents of logrotate config (/etc/logrotate.d/suricata):

/opt/var/log/suricata/_.log  
/opt/var/log/suricata/_.json  
{  
size 5M  
rotate 24  
missingok  
compress  
delaycompress  
create  
dateext  
sharedscripts  
postrotate  
/bin/kill -HUP `cat /usr/local/var/run/suricata.pid 2>/dev/null` 2\>/dev/null || true  
endscript  
}

No differences are observed with functionality no matter if the “Logrotate” script (built by the Ubuntu OS) is located in /etc/cron.daily or /etc/cron.hourly.

Suricata yaml file (pertinent statements)

default-log-dir: /opt/var/log/suricata/

- eve-log:  
enabled: yes  
filetype: regular #regular|syslog|unix\_dgram|unix\_stream|redis  
#filename: eve-%Y-%m-%d-%H:%M.json  
filename: eve.json  
threaded: true

pid-file: /usr/local/var/run/suricata.pid

napatech:  
streams: [“0-70”]

command line statement used to start suricata  
suricata -vvvv -D --pidfile -c /usr/local/var/run/suricata.pid /usr/local/etc/suricata/suricata.yaml --napatech --runmode workers

---

<div class="post-metadata">

**Author:** ![greg](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/greg/32/236_2.png) [@greg](https://forum.suricata.io/u/greg)\
**Post date:** [February 8, 2022, 12:17am UTC](https://forum.suricata.io/t/logrotate-logs-not-rotating/2200/3 "2022-02-08T00:17:29Z")

</div>

This is for rsyslog…

Try adding this line right before the Suricata HUP in the logrotate conf

/bin/kill -HUP `cat /var/run/syslogd.pid 2> /dev/null` 2\> /dev/null || true

Note in line above… there should be a Grave Accent character before  
cat and after the first /dev/null but the site strips that info from  
display

Greg

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [February 8, 2022, 2:45am UTC](https://forum.suricata.io/t/logrotate-logs-not-rotating/2200/4 "2022-02-08T02:45:04Z")

</div>

Also try running the HUP manually. Verify the contents of the PID file is the pid of Suricata, and send it a `kill -HUP <PID>` directly to see if it starts writing to the newly created files.

You can also drop the `create` from logrotate configuration. It could cause problems if running Suricata as a non-root user, and is not needed by Suricata.

---

<div class="post-metadata">

**Author:** ![cadbane](https://avatars.discourse-cdn.com/v4/letter/c/59ef9b/32.png) [@cadbane](https://forum.suricata.io/u/cadbane)\
**Post date:** [February 8, 2022, 3:53am UTC](https://forum.suricata.io/t/logrotate-logs-not-rotating/2200/5 "2022-02-08T03:53:17Z")

</div>

Thank you @greg and @ish for the suggestions. I will implement and monitor.  
Hopefully I report back with good news.

---

<div class="post-metadata">

**Author:** ![cadbane](https://avatars.discourse-cdn.com/v4/letter/c/59ef9b/32.png) [@cadbane](https://forum.suricata.io/u/cadbane)\
**Post date:** [February 8, 2022, 6:12pm UTC](https://forum.suricata.io/t/logrotate-logs-not-rotating/2200/6 "2022-02-08T18:12:58Z")

</div>

Reporting back here.  
I have added **`-HUP cat /var/run/syslogd.pid 2> /dev/null 2>` /dev/null || true** per @greg suggestion and removed the `create` per @ish. This seems to have resolved the issue.  
Logrotate is now working as expected.  
Big Thanks!!
