# Bro 2.5 and log rotation

**URL:** <https://community.zeek.org/t/bro-2-5-and-log-rotation/4561>\
**Category:** Zeek\
**Created:** [December 22, 2016, 1:49pm UTC](https://community.zeek.org/t/bro-2-5-and-log-rotation/4561 "2016-12-22T13:49:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [December 22, 2016, 1:49pm UTC](https://community.zeek.org/t/bro-2-5-and-log-rotation/4561/1 "2016-12-22T13:49:47Z")

</div>

I guess I’m in this boat as well. Since my upgrade, bro will stop rotating logs at some point. I’m not running bro via broctl. Here’s my process for log rotation:

local.bro:  
redef Log::default\_rotation\_interval = 86400 secs;  
redef Log::default\_rotation\_postprocessor\_cmd = “archive-log”;

broctl.cfg:  
LogRotationInterval = 86400

sudo /usr/local/bro/bin/broctl install

sudo ln -s /usr/local/bro/share/broctl/scripts/archive-log /usr/local/bin/  
sudo ln -s /usr/local/bro/share/broctl/scripts/broctl-config.sh /usr/local/bin/  
sudo ln -s /usr/local/bro/share/broctl/scripts/make-archive-name /usr/local/bin/  
sudo ln -s /usr/local/bro/share/broctl/scripts/expire-logs /usr/local/bin/  
sudo ln -s /usr/local/bro/share/broctl/scripts/delete-log /usr/local/bin/  
sudo ln -s /usr/local/bro/share/broctl/scripts/cflow-stats /usr/local/bin/  
sudo ln -s /usr/local/bro/share/broctl/scripts/stats-to-csv /usr/local/bin/

This will work for a while. But at some point it stops:

 ![](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/c98c9146e854ebce9278dc255e670b0f95d4d3a2.png)

at the core I believe it’s because bro, after sometime, won’t respond to a “normal” kill command. A “sudo killall bro” will do nothing. Usually I’ll “sudo killall bro”, wait a minute, and then my spool directory will be empty, I’ll have an email with stats, and I’ll have my new archive directory. I’ll have to -9 it in order to get it to stop, I’ve restarted this morning and will see how many days it will go. Thank you.

James

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [January 4, 2017, 3:00am UTC](https://community.zeek.org/t/bro-2-5-and-log-rotation/4561/2 "2017-01-04T03:00:09Z")

</div>

I've seen this before when people are generating really huge logs and IO on their system goes crazy because the previous logs are still being compressed which runs into a downward spiral that it never recovers from. For those logs that you have which haven't been rotated as you expected, was there a gzip process running in the background? I suspect that you have a lot of gzip processes running and a very high system load.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![James\_inthe\_box](https://avatars.discourse-cdn.com/v4/letter/j/6f9a4e/32.png) [@James\_inthe\_box](https://community.zeek.org/u/James_inthe_box)\
**Post date:** [January 4, 2017, 11:19am UTC](https://community.zeek.org/t/bro-2-5-and-log-rotation/4561/3 "2017-01-04T11:19:30Z")

</div>

Thanks Seth,

Interestingly, this is on my home network…the largest compressed file in looking at past logs was tcprecovery at 7.8 megs. On a hunch, after this issue came up again on Christmas day, I disabled TCPRS and have had no issues since.

James

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:44pm UTC](https://community.zeek.org/t/bro-2-5-and-log-rotation/4561/4 "2022-05-06T15:44:25Z")

</div>


