public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
From: Adolf Belka <adolf.belka@ipfire.org>
To: "IPFire: Development-List" <development@lists.ipfire.org>
Subject: Question about potential consequence of patch to rotate Suricata logs daily.
Date: Tue, 21 Apr 2026 18:20:05 +0200	[thread overview]
Message-ID: <d687ca17-feea-46f5-93ca-1807d6ee5c6c@ipfire.org> (raw)

Hi Michael,

I saw that patch

https://git.ipfire.org/?p=ipfire-2.x.git;a=commit;h=30ccb9ed80ee3ad70403794da4c937fd183b9bd8

had been created.

It seems to me that this change will mean that there will only ever be 52 days worth of logs for Suricata. The global value for rotate is 52 which is intended to give a tear's worth of data for the various graphs.

With the Suricata logs being rotated daily and with the same global rotate value ( there is no modified rotate value for the Suricata section) then there will only ever be 52 days worth of Suricata Logs. This will mean that the Suricata throughput graph will only show about 7 weeks worth of data when the Year option is selected.

Was this the intent?

If not then there probably needs to be a rotate entry in the Suricata section with rotate 393 to give a year's worth of data but then that will put back the same amount of logs for people who have very small disk drives.

If yes then maybe the Year option on the Suricata graph should be removed or changed to 7 weeks as the 52 days would then be around 7.5 weeks of data available.

It could also be that I am not familiar enough with the rotate package and therefore my concerns are not valid. So I am open to getting clarification.

Best regards,

Adolf.


             reply	other threads:[~2026-04-21 16:20 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-04-21 16:20 Adolf Belka [this message]
2026-04-21 17:05 ` Bernhard Bitsch
2026-04-21 20:08   ` Adolf Belka
2026-04-22  6:17     ` Michael Tremer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=d687ca17-feea-46f5-93ca-1807d6ee5c6c@ipfire.org \
    --to=adolf.belka@ipfire.org \
    --cc=development@lists.ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox