# archive-log process apparently failing

**URL:** <https://community.zeek.org/t/archive-log-process-apparently-failing/3869>\
**Category:** Zeek\
**Created:** [October 16, 2015, 6:15pm UTC](https://community.zeek.org/t/archive-log-process-apparently-failing/3869 "2015-10-16T18:15:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![John\_Daly](https://avatars.discourse-cdn.com/v4/letter/j/c57346/32.png) [@John\_Daly](https://community.zeek.org/u/John_Daly)\
**Post date:** [October 16, 2015, 6:15pm UTC](https://community.zeek.org/t/archive-log-process-apparently-failing/3869/1 "2015-10-16T18:15:03Z")

</div>

Brad,

At the time of log rotation, Bro copies all logs from the "current"  
dir (more accurately spool/manager) to the archive directory  
(logs/YYYY-MM-DD) and gzips the logs. Be sure that you have CPU and IO  
cycles to do both of those tasks. If you want to optimize this, tweak  
the following settings in the broctl.cfg:

\* Set CompressLogs = 0. This will prevent broctl from compressing the  
logs, freeing up CPU cycles at log rotation time.

\* Set TraceSummary = "". This will prevent the connection summary  
script from being run, freeing up CPU cycles at log rotation time.

-jd

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:43pm UTC](https://community.zeek.org/t/archive-log-process-apparently-failing/3869/2 "2022-05-06T15:43:09Z")

</div>


