# What does happen to Suricata when a log rotation is made?

**URL:** <https://forum.suricata.io/t/what-does-happen-to-suricata-when-a-log-rotation-is-made/3699>\
**Category:** Help\
**Tags:** suricata\
**Created:** [July 14, 2023, 10:12am UTC](https://forum.suricata.io/t/what-does-happen-to-suricata-when-a-log-rotation-is-made/3699 "2023-07-14T10:12:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikel95](https://avatars.discourse-cdn.com/v4/letter/m/94ad74/32.png) [@mikel95](https://forum.suricata.io/u/mikel95)\
**Post date:** [July 14, 2023, 10:12am UTC](https://forum.suricata.io/t/what-does-happen-to-suricata-when-a-log-rotation-is-made/3699/1 "2023-07-14T10:12:00Z")

</div>

Hello,

I am now configuring a log rotation for Suricata logs. And I have seen that the logrotate example configuration for suricata runs this after a rotation:

```auto
/bin/kill -HUP `cat @e_rundir@suricata.pid 2> /dev/null` 2> /dev/null || true

```

I would like to understand what happens exactly to suricata when this runs. I have read that the kill -HUP sends a notification to the process that the terminal connection is lost and that it must restart itself.

But what does this mean in terms of Suricata? Does it restart the whole process?(I already know that not completely because of the time it takes to restart completely) Does it just restart the outputs files?Up to what point it is restarted? Does it stop sniffing for a moment? Do packages get stored in a buffer until restart?

So that’s it, if someone can explain me what does Suricata precisely do when receives the HUP signal, I would appreciate.

Thanks

---

<div class="post-metadata">

**Author:** ![Jeff\_Lucovsky](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/jeff_lucovsky/32/11_2.png) [@Jeff\_Lucovsky](https://forum.suricata.io/u/Jeff_Lucovsky)\
**Post date:** [July 14, 2023, 2:14pm UTC](https://forum.suricata.io/t/what-does-happen-to-suricata-when-a-log-rotation-is-made/3699/2 "2023-07-14T14:14:49Z")

</div>

When `SIGHUP` is received by Suricata, it will mark all of the log files such that they’re closed an re-opened. Suricata doesn’t restart.

There’ll be no disruption of traffic processing.

`SIGHUP` should be sent _after_ the logs are rotated – Suricata doesn’t rotate logs – to cause Suricata to close its filehandle and re-open – in essence, it’s recreating the file that _was just rotated_
