From: Adolf Belka <adolf.belka@ipfire.org>
To: Bernhard Bitsch <bbitsch@ipfire.org>
Cc: "IPFire: Development-List" <development@lists.ipfire.org>
Subject: Re: Question about potential consequence of patch to rotate Suricata logs daily.
Date: Tue, 21 Apr 2026 22:08:00 +0200 [thread overview]
Message-ID: <bf9739ca-e5d9-48ef-af8f-7af1ecfb10d0@ipfire.org> (raw)
In-Reply-To: <cc727c11-79c4-420e-8818-aa8729caa7e6@ipfire.org>
Hi Bernhard,
Thanks for the clarification. So my worries were unfounded, good to know.
Regards,
Adolf.
On 21/04/2026 19:05, Bernhard Bitsch wrote:
> Hi,
>
> the IPS graphs are generated from the iptables collectd samplings.
> They are independent from the log files.
> The log section of the WUI isn't touched, also. It depends on /var/log/suricata/{fast|alert}.log only.
>
> BR,
> Bernhard
>
> Am 21.04.2026 um 18:20 schrieb Adolf Belka:
>> Hi Michael,
>>
>> I saw that patch
>>
>> https://git.ipfire.org/? p=ipfire-2.x.git;a=commit;h=30ccb9ed80ee3ad70403794da4c937fd183b9bd8
>>
>> had been created.
>>
>> It seems to me that this change will mean that there will only ever be 52 days worth of logs for Suricata. The global value for rotate is 52 which is intended to give a tear's worth of data for the various graphs.
>>
>> With the Suricata logs being rotated daily and with the same global rotate value ( there is no modified rotate value for the Suricata section) then there will only ever be 52 days worth of Suricata Logs. This will mean that the Suricata throughput graph will only show about 7 weeks worth of data when the Year option is selected.
>>
>> Was this the intent?
>>
>> If not then there probably needs to be a rotate entry in the Suricata section with rotate 393 to give a year's worth of data but then that will put back the same amount of logs for people who have very small disk drives.
>>
>> If yes then maybe the Year option on the Suricata graph should be removed or changed to 7 weeks as the 52 days would then be around 7.5 weeks of data available.
>>
>> It could also be that I am not familiar enough with the rotate package and therefore my concerns are not valid. So I am open to getting clarification.
>>
>> Best regards,
>>
>> Adolf.
>>
>
>
next prev parent reply other threads:[~2026-04-21 20:08 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-04-21 16:20 Adolf Belka
2026-04-21 17:05 ` Bernhard Bitsch
2026-04-21 20:08 ` Adolf Belka [this message]
2026-04-22 6:17 ` Michael Tremer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=bf9739ca-e5d9-48ef-af8f-7af1ecfb10d0@ipfire.org \
--to=adolf.belka@ipfire.org \
--cc=bbitsch@ipfire.org \
--cc=development@lists.ipfire.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox