# ascii logger: unexpected modification to default\_rotation\_postprocessor\_cmd and default\_rotation\_date\_format during runtime

**URL:** <https://community.zeek.org/t/ascii-logger-unexpected-modification-to-default-rotation-postprocessor-cmd-and-default-rotation-date-format-during-runtime/5305>\
**Category:** Zeek\
**Created:** [May 15, 2018, 10:28am UTC](https://community.zeek.org/t/ascii-logger-unexpected-modification-to-default-rotation-postprocessor-cmd-and-default-rotation-date-format-during-runtime/5305 "2018-05-15T10:28:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Franky](https://avatars.discourse-cdn.com/v4/letter/f/958977/32.png) [@Franky](https://community.zeek.org/u/Franky)\
**Post date:** [May 15, 2018, 10:28am UTC](https://community.zeek.org/t/ascii-logger-unexpected-modification-to-default-rotation-postprocessor-cmd-and-default-rotation-date-format-during-runtime/5305/1 "2018-05-15T10:28:11Z")

</div>

Hi!

I noticed a strange behavior: my bro 2.5.3 running on Linux for about 15  
days suddenly "forgot" my settings for  
Log::default\_rotation\_postprocessor\_cmd and  
Log::default\_rotation\_date\_format.

When the change happened, the rotated files piled up, because the  
post-processing script was not started. Also the filenames did no  
longer contain the time zone. (I use Log::default\_rotation\_date\_format =  
%Y-%m-%d-%H-%M-%S%Z to avoid file name collisions when switching  
to/from daylight-saving time).

A quick look at the code was not enough to understand the way rotation  
works. I can spend more time, if nobody comes up with an explanation. I  
can only assume, that some internal error in bro resets the values  
without an error showing up (or the error was lost in bro's tmux  
session).

Restarting bro helped for now.

Thanks for any ideas.

Franky.

---

<div class="post-metadata">

**Author:** ![seth](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/seth/32/642_2.png) [@seth](https://community.zeek.org/u/seth)\
**Post date:** [May 15, 2018, 6:59pm UTC](https://community.zeek.org/t/ascii-logger-unexpected-modification-to-default-rotation-postprocessor-cmd-and-default-rotation-date-format-during-runtime/5305/2 "2018-05-15T18:59:10Z")

</div>

This has been a long standing bug that only ever seems to express itself on heavily loaded systems but generally seems to be somewhat rare. We haven't been able to find the exact bug yet, but some of us have known about it for quite a while. It would help if we could reproduce it reliably, but I suspect that in order to reproduce it we need to fully understand it first. 🙂

&nbsp;&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Franky](https://avatars.discourse-cdn.com/v4/letter/f/958977/32.png) [@Franky](https://community.zeek.org/u/Franky)\
**Post date:** [May 16, 2018, 5:57am UTC](https://community.zeek.org/t/ascii-logger-unexpected-modification-to-default-rotation-postprocessor-cmd-and-default-rotation-date-format-during-runtime/5305/3 "2018-05-16T05:57:51Z")

</div>

Hi!

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/ascii-logger-unexpected-modification-to-default-rotation-postprocessor-cmd-and-default-rotation-date-format-during-runtime/5305/4 "2022-05-06T15:45:47Z")

</div>


