New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

file rotation for 'file_output' #266

Closed
krishnaghatti opened this Issue Aug 13, 2017 · 2 comments

Comments

Projects
None yet
3 participants
@krishnaghatti

krishnaghatti commented Aug 13, 2017

Hello all,

I am using file_output with the below settings. Is there any way we can set rotation of the file after it reaches a specific size or time (rotate once every day)

file_output:
enabled: true
filename: /var/log/falco/events.txt

@finid

This comment has been minimized.

finid commented Sep 18, 2017

On Ubuntu and maybe other distros too, you can use the installed Logrotate program. See /etc/logrotate.d and /etc/logrotate.conf.

By the way, my config is just like yours.

@mstemm mstemm referenced this issue Apr 5, 2018

Merged

Rotate logs #347

@mstemm

This comment has been minimized.

Contributor

mstemm commented Apr 5, 2018

#347 will have an example logrotate config. Also, it modifies falco to close/reopen file and program outputs on SIGUSR1. This is relevant when using keep_alive: true, as the output file/program is kept open across outputs.

@mstemm mstemm closed this in #347 Apr 5, 2018

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment