Updated: 28 September 2026 · Applies to: logrotate 3.18 to 3.22 on AlmaLinux and Rocky Linux 9 and 10, RHEL 9 and 10, Ubuntu 24.04 and 26.04, Debian 13
logrotate keeps log files from filling the disk: it renames the current log, starts a new one, compresses the old ones and deletes the oldest. System packages set it up for their own logs; you add a small file for your application's logs. On current distributions a systemd timer runs it once a day (logrotate.timer). We tested the example below with logrotate's dry-run mode on AlmaLinux 9.
How it is organised
/etc/logrotate.conf: global defaults (for exampleweekly,rotate 4,create)./etc/logrotate.d/: one file per application; these override the defaults.systemctl list-timers logrotate.timer: when it runs next.
Add rotation for your application
Create /etc/logrotate.d/myapp:
/var/log/myapp/*.log {
daily
rotate 14
compress
delaycompress
missingok
notifempty
create 0640 root root
dateext
}
dailyandrotate 14: rotate every day and keep 14 old logs.compressanddelaycompress: gzip old logs, but keep the most recent one uncompressed for a day, in case a program still writes to it.missingokandnotifempty: no error if the log is missing, and no rotation if it is empty.create 0640 root root: create the new log with these permissions and owner.dateext: add the date to rotated files instead of a number.
Tell the program about the new file
A program that keeps its log file open continues writing into the renamed file. Either ask it to reopen its logs after rotation:
sharedscripts
postrotate
systemctl reload myapp >/dev/null 2>&1 || true
endscript
or, if the program cannot reopen its log, use copytruncate instead of create: logrotate copies the log and empties the original. A few lines written during the copy can be lost.
Test it
logrotate -d /etc/logrotate.d/myapp # dry run: shows what would happen logrotate -f /etc/logrotate.d/myapp # rotate now, even if not due
-d changes nothing and prints the decisions for each file, which also reveals syntax errors.
Other useful options
size 100M: rotate when the file reaches this size (checked when logrotate runs).maxage 30: delete rotated logs older than 30 days.su myuser mygroup: needed when the log folder belongs to a non-root user.
Common problems
- "duplicate log entry": the same file is listed in two configuration files. Keep it in only one.
- "skipping ... because parent directory has insecure permissions": add a
suline with the folder's owner and group. - Old logs are never deleted: check that
rotateis set and that the timer runs.
Official documentation: logrotate manual page.
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
