Project

General

Profile

Actions

Feature #1636

closed

Signal rotation of unified2 log file without restart

Added by Brian Hennigar almost 9 years ago. Updated almost 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

It would be good to have the ability of rotating the log files without having to stop/start the Suricata process. Something similar to the SIGUSR2 for the live rule reload.

From OISF user group:

- Give the unified2 output a "nostamp" option like Snort.
- If nostamp is on, subject the unified2 output to HUP file rotation.

Then you could do file rotation like you would done on other output
files like eve. Move the existing one out of the way, HUP Suricata to
start writing to a new file.

Actions

Also available in: Atom PDF