Quote from: BrandyWine on October 15, 2025, 09:23:52 PMWhat more info is needed? What should I look at?
Logs are being rotated daily, settings say weekly.
More than 4 logs are saved, settings say save 4.
gotta admit, i have mine set at 2 weekly, and i only have 2... i was about to say "that's 4 weeks of logs..." but i only have two files and 2 + weekly... not sure if either of our retention is matching the configured state
i did figure out how to enable manual rotation of an extra suricata log file i have created through the use of suricata's custom.yaml, and this file has stuck around through several upgrades
file name example:
/usr/local/etc/newsyslog.conf.d/suricataxff.conf:
content example:
# logfilename [owner:group] mode count size when flags [/pid_file] [sig_num]
/var/log/suricata/evexff.json root:wheel 640 1 500000 $W0D23 B /var/run/suricata.pid 1
"