# Rotate logs individually?

**URL:** <https://community.zeek.org/t/rotate-logs-individually/5104>\
**Category:** Zeek\
**Created:** [November 20, 2017, 12:26pm UTC](https://community.zeek.org/t/rotate-logs-individually/5104 "2017-11-20T12:26:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![craig\_bowser](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@craig\_bowser](https://community.zeek.org/u/craig_bowser)\
**Post date:** [November 20, 2017, 12:26pm UTC](https://community.zeek.org/t/rotate-logs-individually/5104/1 "2017-11-20T12:26:56Z")

</div>

We have one particular bro log that fills up much faster than all the others. Is there a way to rotate that one log one a different timetable than the others?

I found this in the documentation which seems to indicate that it is possible (the example given is for the conn.log):

[https://www.bro.org/sphinx-git/frameworks/logging.html#rotation](https://www.bro.org/sphinx-git/frameworks/logging.html#rotation)

event bro\_init()

{

local f = Log::get\_filter(Conn::LOG, “default”);

f$interv = 30 min;

Log::add\_filter(Conn::LOG, f);

}

Can you put this script into /usr/local/bro/share/bro/site/local.bro to force only that log to rotate on a different schedule?

Thanks.

---

<div class="post-metadata">

**Author:** ![Daniel\_Thayer](https://avatars.discourse-cdn.com/v4/letter/d/8dc957/32.png) [@Daniel\_Thayer](https://community.zeek.org/u/Daniel_Thayer)\
**Post date:** [November 20, 2017, 1:52pm UTC](https://community.zeek.org/t/rotate-logs-individually/5104/2 "2017-11-20T13:52:23Z")

</div>

It works for me.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/rotate-logs-individually/5104/3 "2022-05-06T15:45:25Z")

</div>


