Updated: 28 September 2026 · Applies to: logrotate 3.18 to 3.22 on AlmaLinux and Rocky Linux 9 and 10, RHEL 9 and 10, Ubuntu 24.04 and 26.04, Debian 13

logrotate keeps log files from filling the disk: it renames the current log, starts a new one, compresses the old ones and deletes the oldest. System packages set it up for their own logs; you add a small file for your application's logs. On current distributions a systemd timer runs it once a day (logrotate.timer). We tested the example below with logrotate's dry-run mode on AlmaLinux 9.

How it is organised

  • /etc/logrotate.conf: global defaults (for example weekly, rotate 4, create).
  • /etc/logrotate.d/: one file per application; these override the defaults.
  • systemctl list-timers logrotate.timer: when it runs next.

Add rotation for your application

Create /etc/logrotate.d/myapp:

/var/log/myapp/*.log {
    daily
    rotate 14
    compress
    delaycompress
    missingok
    notifempty
    create 0640 root root
    dateext
}
  • daily and rotate 14: rotate every day and keep 14 old logs.
  • compress and delaycompress: gzip old logs, but keep the most recent one uncompressed for a day, in case a program still writes to it.
  • missingok and notifempty: no error if the log is missing, and no rotation if it is empty.
  • create 0640 root root: create the new log with these permissions and owner.
  • dateext: add the date to rotated files instead of a number.

Tell the program about the new file

A program that keeps its log file open continues writing into the renamed file. Either ask it to reopen its logs after rotation:

    sharedscripts
    postrotate
        systemctl reload myapp >/dev/null 2>&1 || true
    endscript

or, if the program cannot reopen its log, use copytruncate instead of create: logrotate copies the log and empties the original. A few lines written during the copy can be lost.

Test it

logrotate -d /etc/logrotate.d/myapp     # dry run: shows what would happen
logrotate -f /etc/logrotate.d/myapp     # rotate now, even if not due

-d changes nothing and prints the decisions for each file, which also reveals syntax errors.

Other useful options

  • size 100M: rotate when the file reaches this size (checked when logrotate runs).
  • maxage 30: delete rotated logs older than 30 days.
  • su myuser mygroup: needed when the log folder belongs to a non-root user.

Common problems

  • "duplicate log entry": the same file is listed in two configuration files. Keep it in only one.
  • "skipping ... because parent directory has insecure permissions": add a su line with the folder's owner and group.
  • Old logs are never deleted: check that rotate is set and that the timer runs.

Official documentation: logrotate manual page.

Ucartz services for this topic

Was this answer helpful? 0 Users Found This Useful (0 Votes)