# log rotation leaving conn.log unrotated

**URL:** <https://community.zeek.org/t/log-rotation-leaving-conn-log-unrotated/3573>\
**Category:** Zeek\
**Created:** [April 27, 2015, 3:41pm UTC](https://community.zeek.org/t/log-rotation-leaving-conn-log-unrotated/3573 "2015-04-27T15:41:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Franky](https://avatars.discourse-cdn.com/v4/letter/f/958977/32.png) [@Franky](https://community.zeek.org/u/Franky)\
**Post date:** [April 27, 2015, 3:41pm UTC](https://community.zeek.org/t/log-rotation-leaving-conn-log-unrotated/3573/1 "2015-04-27T15:41:10Z")

</div>

Hi.

Before I ask yet another question, I wanted to say thanks to all who helped me  
during the last weeks. 🙂 All tips where very helpful and fast! I hope I can repay  
for this by contributing in the future.

I have this simple bro file:

redef Log::default\_rotation\_postprocessor\_cmd = “./postrotate.sh”;  
redef Log::default\_rotation\_interval = 10 sec;

with postrotate.sh just printing the parameters:

#!/bin/sh  
echo “-1-”  
echo $1  
echo $2  
echo $3  
echo $4  
echo $5  
echo $6  
echo “-2-”

Now when bro is terminated via CTRL-C, the script is called:

1430147916.038582 received termination signal  
1430147916.038582 1865 packets received on interface eth0, 45 dropped

-1-  
files.2015-04-27-17-18-30.log  
files  
15-04-27\_17.18.30  
15-04-27\_17.18.36  
1  
ascii  
-2-  
-1-  
http.2015-04-27-17-18-30.log  
http  
15-04-27\_17.18.30  
15-04-27\_17.18.36  
1  
ascii  
-2-  
-1-  
weird.2015-04-27-17-18-30.log  
weird  
15-04-27\_17.18.30  
15-04-27\_17.18.36  
1  
ascii  
-2-  
-1-  
conn.2015-04-27-17-18-30.log  
conn  
15-04-27\_17.18.30  
15-04-27\_17.18.36  
1  
ascii  
-2-  
-1-  
reporter.2015-04-27-17-18-36.log  
reporter  
15-04-27\_17.18.36  
15-04-27\_17.18.36  
1  
ascii  
-2-

After that there is still a conn.log around. Why is this file not rotated?

When I restart bro now, the conn.log seems to be overwritten and  
entries for example in files.log reference a uid not found in any of  
the conn.logs.

I could not figure out why rotation works for most of the logs, but  
not for conn.log.

Franky

---

<div class="post-metadata">

**Author:** ![Daniel\_Thayer](https://avatars.discourse-cdn.com/v4/letter/d/8dc957/32.png) [@Daniel\_Thayer](https://community.zeek.org/u/Daniel_Thayer)\
**Post date:** [April 27, 2015, 6:34pm UTC](https://community.zeek.org/t/log-rotation-leaving-conn-log-unrotated/3573/2 "2015-04-27T18:34:52Z")

</div>

In your example, conn.log was rotated (the new filename was conn.2015-04-27-17-18-30.log). The conn.log file you saw  
after terminating Bro was most likely created in the short time span  
between rotating conn.log and Bro termination.

---

<div class="post-metadata">

**Author:** ![Franky](https://avatars.discourse-cdn.com/v4/letter/f/958977/32.png) [@Franky](https://community.zeek.org/u/Franky)\
**Post date:** [April 28, 2015, 8:46am UTC](https://community.zeek.org/t/log-rotation-leaving-conn-log-unrotated/3573/3 "2015-04-28T08:46:10Z")

</div>

hi,

> > 
> 
> In your example, conn.log was rotated (the new filename was conn.2015-04-27-17-18-30.log). The conn.log file you saw after terminating Bro was most likely created in the short time span between rotating conn.log and Bro termination.

I think there is more to this. If repeat the following steps I do loose some entries in conn.log:

1. start bro
2. produce some traffic
3. stop bro via CTRL-C
4. restart bro
5. wait for log rotation
6. stop bro via CTRL-C

grep for conn\_uids from files.log. For some entries in files.log there will be no match in any  
of the conn.logs. My workaround for now is to append the stale  
conn.log to the last rotated log on shutdown:

file\_name=$1  
base\_name=$2  
from=$3  
to=$4  
terminating=$5  
writer=$6

echo “[+] LOG: Rotating $file\_name (base: $base\_name, from: $from, to: $to, terminating: $terminating, writer: $writer)”

if [$terminating -eq 1 -a -f $base\_name.log]; then  
echo "terminating. appending stale $base\_name.log "

# cut timestamp

head -n-1 $file\_name \> $file\_name.tmp  
mv $file\_name.tmp $file\_name

# cut header

tail -n +9 $base\_name.log \>\> $file\_name  
mv $base\_name.log done.log  
fi

I don’t have the time right now, but I will look further into this.

Franky

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:42pm UTC](https://community.zeek.org/t/log-rotation-leaving-conn-log-unrotated/3573/4 "2022-05-06T15:42:37Z")

</div>


