DEV Community

Janak Shrestha
Janak Shrestha

Posted on

Linux LogRotate

The Nautilus DevOps team is ready to launch a new application, which they will deploy on app servers in Stratos Datacenter. They are expecting significant traffic/usage of tomcat on app servers after that. This will generate massive logs, creating huge log files. To utilise the storage efficiently, they need to compress the log files and need to rotate old logs. Check the requirements shared below:

a. In all app servers install tomcat package.

b. Using logrotate configure tomcat logs rotation to monthly and keep only 3 rotated logs.

(If by default log rotation is set, then please update configuration as needed)


Introduction

Log files are essential for troubleshooting, auditing, and monitoring applications. However, without proper management, log files can grow uncontrollably, consuming disk space and potentially causing service outages. LogRotate is a Linux utility that automates the rotation, compression, and removal of log files, ensuring efficient use of storage.

This guide walks through a real-world scenario where the Nautilus DevOps team needed to install Tomcat on three application servers and configure logrotate to rotate Tomcat logs monthly while keeping only three rotated logs.


Environment Details

Server Hostname User Password
App Server 1 stapp01 tony Ir0nM@n
App Server 2 stapp02 steve Am3ric@
App Server 3 stapp03 banner BigGr33n
Jump Host jump-host thor mjolnir123

Understanding LogRotate

What is LogRotate

LogRotate is a Linux utility that manages log files by rotating them based on size or time. It prevents log files from growing indefinitely, compresses old logs to save space, and removes the oldest logs based on a retention policy.

Key Concepts

Concept Description
Rotation Moving the current log to a new file and starting fresh
Compression Reducing the size of rotated logs using gzip
Retention Number of rotated logs to keep before deletion
Frequency How often rotation occurs (daily, weekly, monthly)

Why Use LogRotate

LogRotate provides several benefits. It prevents disk space exhaustion by keeping log files at manageable sizes. It preserves historical data for troubleshooting and auditing. It automates routine maintenance, reducing manual intervention. It compresses old logs to save storage space. It integrates with systemd timers for reliable scheduling.


Prerequisites

Before beginning, ensure the following are available. You need SSH access to all three app servers with sudo or root privileges. You should have basic knowledge of Linux commands. The servers should have network access to package repositories.


Step 1: Connect to App Server 1

Access the server using SSH.

ssh tony@stapp01
Password: Ir0nM@n
Enter fullscreen mode Exit fullscreen mode

Switch to root to perform administrative tasks.

sudo su -
Password: Ir0nM@n
Enter fullscreen mode Exit fullscreen mode

Step 2: Install Tomcat

Install Tomcat using the package manager. On CentOS Stream 9, Tomcat is available in the AppStream repository.

yum install -y tomcat
Enter fullscreen mode Exit fullscreen mode

The installation pulls in several dependencies.

Package Purpose
tomcat Main Tomcat server
tomcat-lib Core libraries
tomcat-servlet-4.0-api Servlet API
tomcat-jsp-2.3-api JSP API
tomcat-el-3.0-api Expression Language API
ecj Eclipse Compiler for Java
apr Apache Portable Runtime
tomcat-native Native library for performance

Verify the installation.

rpm -q tomcat
Enter fullscreen mode Exit fullscreen mode

Expected output.

tomcat-9.0.120-1.el9.noarch
Enter fullscreen mode Exit fullscreen mode

Step 3: Start and Enable Tomcat

Start the Tomcat service and enable it to start on boot.

systemctl start tomcat
systemctl enable tomcat
systemctl status tomcat
Enter fullscreen mode Exit fullscreen mode

The status output should show the service is active and running.

● tomcat.service - Apache Tomcat Web Application Container
     Loaded: loaded (/usr/lib/systemd/system/tomcat.service; enabled; preset: disabled)
     Active: active (running) since Mon 2026-09-28 11:49:38 UTC; 359ms ago
   Main PID: 6545 (java)
Enter fullscreen mode Exit fullscreen mode

Why Start the Service

Starting Tomcat generates the log files that logrotate will manage. Without running the service, the log directory remains empty.


Step 4: Verify Log Files are Generated

Check the Tomcat log directory.

ls -la /var/log/tomcat/
Enter fullscreen mode Exit fullscreen mode

Expected output.

-rw-r--r-- 1 tomcat tomcat 7321 Sep 28 11:49 catalina.2026-09-28.log
-rw-r--r-- 1 tomcat tomcat    0 Sep 28 11:49 host-manager.2026-09-28.log
-rw-r--r-- 1 tomcat tomcat    0 Sep 28 11:49 localhost.2026-09-28.log
-rw-r--r-- 1 tomcat tomcat    0 Sep 28 11:49 localhost_access_log.2026-09-28.txt
-rw-r--r-- 1 tomcat tomcat    0 Sep 28 11:49 manager.2026-09-28.log
Enter fullscreen mode Exit fullscreen mode
Log File Purpose
catalina.log Main Tomcat log
host-manager.log Host Manager application log
localhost.log Localhost application log
localhost_access_log.txt HTTP access log
manager.log Manager application log

Step 5: Install LogRotate

Check if logrotate is installed.

rpm -q logrotate
Enter fullscreen mode Exit fullscreen mode

If not installed, install it.

yum install -y logrotate
Enter fullscreen mode Exit fullscreen mode

The installation creates a systemd timer for logrotate.

Created symlink /etc/systemd/system/timers.target.wants/logrotate.timer → /usr/lib/systemd/system/logrotate.timer.
Enter fullscreen mode Exit fullscreen mode

Step 6: Create the LogRotate Configuration

Create a configuration file for Tomcat at /etc/logrotate.d/tomcat.

vi /etc/logrotate.d/tomcat
Enter fullscreen mode Exit fullscreen mode

Add the following configuration.

/var/log/tomcat/*.log {
    monthly
    rotate 3
    compress
    missingok
    notifempty
    copytruncate
}
Enter fullscreen mode Exit fullscreen mode

Configuration Directive Breakdown

Directive Purpose
monthly Rotate logs once per month
rotate 3 Keep only 3 rotated log files
compress Compress rotated logs with gzip
missingok Do not error if log file is missing
notifempty Do not rotate empty log files
copytruncate Copy then truncate original log

Why copytruncate is Essential

Tomcat keeps log files open while running. Without copytruncate, logrotate would rename the log file, but Tomcat would continue writing to the renamed file. The new log file would remain empty. The copytruncate directive copies the log file and then truncates the original, allowing Tomcat to continue writing to the same file without interruption.


Step 7: Verify the Configuration

Test the configuration with a dry run.

logrotate -d /etc/logrotate.d/tomcat
Enter fullscreen mode Exit fullscreen mode

Expected output.

reading config file /etc/logrotate.d/tomcat
Reading state from file: /var/lib/logrotate/logrotate.status
Allocating hash table for state file, size 64 entries

Handling 1 logs

rotating pattern: /var/log/tomcat/*.log  monthly (3 rotations)
empty log files are not rotated, old logs are removed
considering log /var/log/tomcat/catalina.2026-09-28.log
  Now: 2026-09-28 11:52
  Last rotated at 2026-09-28 11:00
  log does not need rotating (log has already been rotated)
Enter fullscreen mode Exit fullscreen mode

The dry run shows what logrotate would do without making changes.


Step 8: Apply to App Server 2

Connect to stapp02 and repeat the process.

ssh steve@stapp02
sudo su -
Password: Am3ric@
Enter fullscreen mode Exit fullscreen mode
yum install -y tomcat
yum install -y logrotate

systemctl start tomcat
systemctl enable tomcat

cat > /etc/logrotate.d/tomcat << 'EOF'
/var/log/tomcat/*.log {
    monthly
    rotate 3
    compress
    missingok
    notifempty
    copytruncate
}
EOF

logrotate -d /etc/logrotate.d/tomcat
Enter fullscreen mode Exit fullscreen mode

Step 9: Apply to App Server 3

Connect to stapp03 and repeat the process.

ssh banner@stapp03
sudo su -
Password: BigGr33n
Enter fullscreen mode Exit fullscreen mode
yum install -y tomcat
yum install -y logrotate

systemctl start tomcat
systemctl enable tomcat

cat > /etc/logrotate.d/tomcat << 'EOF'
/var/log/tomcat/*.log {
    monthly
    rotate 3
    compress
    missingok
    notifempty
    copytruncate
}
EOF

logrotate -d /etc/logrotate.d/tomcat
Enter fullscreen mode Exit fullscreen mode

Step 10: Verify All Servers

Run verification commands on all servers.

# Check Tomcat service
ssh tony@stapp01 "systemctl is-active tomcat"
ssh steve@stapp02 "systemctl is-active tomcat"
ssh banner@stapp03 "systemctl is-active tomcat"

# Check logrotate configuration
ssh tony@stapp01 "cat /etc/logrotate.d/tomcat"
ssh steve@stapp02 "cat /etc/logrotate.d/tomcat"
ssh banner@stapp03 "cat /etc/logrotate.d/tomcat"

# Check log files
ssh tony@stapp01 "sudo ls -la /var/log/tomcat/"
ssh steve@stapp02 "sudo ls -la /var/log/tomcat/"
ssh banner@stapp03 "sudo ls -la /var/log/tomcat/"
Enter fullscreen mode Exit fullscreen mode

Understanding the Rotation Process

Before Rotation

/var/log/tomcat/catalina.2026-09-28.log
Enter fullscreen mode Exit fullscreen mode

After Rotation

/var/log/tomcat/catalina.2026-09-28.log.1.gz
Enter fullscreen mode Exit fullscreen mode

After Multiple Rotations

/var/log/tomcat/catalina.2026-09-28.log.1.gz
/var/log/tomcat/catalina.2026-09-28.log.2.gz
/var/log/tomcat/catalina.2026-09-28.log.3.gz
Enter fullscreen mode Exit fullscreen mode

When the fourth rotation occurs, the oldest file (.3.gz) is deleted, and the others are renamed to make room for the new rotation.


Verification Checklist

Check Command Expected
Tomcat installed rpm -q tomcat tomcat-9.0.120
Tomcat running systemctl is-active tomcat active
logrotate installed rpm -q logrotate logrotate-3.18.0
Config file exists cat /etc/logrotate.d/tomcat Configuration content
Dry run passes logrotate -d /etc/logrotate.d/tomcat No errors
Log files exist ls -la /var/log/tomcat/ Log files listed

Troubleshooting Common Issues

Issue 1: logrotate Command Not Found

Install the logrotate package.

yum install -y logrotate
Enter fullscreen mode Exit fullscreen mode

Issue 2: State File Warning

When running logrotate for the first time, you may see a warning about the state file. This is normal. LogRotate creates the state file automatically when it runs for the first time during a real rotation cycle.

Issue 3: Logs Not Rotating

Check that the logrotate timer is active.

systemctl status logrotate.timer
Enter fullscreen mode Exit fullscreen mode

Check the logrotate status.

cat /var/lib/logrotate/logrotate.status
Enter fullscreen mode Exit fullscreen mode

Issue 4: Tomcat Not Writing to New Logs

Ensure copytruncate is in the configuration. Without it, Tomcat may continue writing to the old log file.

Issue 5: Configuration Syntax Errors

Verify the configuration syntax.

logrotate -d /etc/logrotate.d/tomcat
Enter fullscreen mode Exit fullscreen mode

Fix any syntax errors before the next rotation cycle.


Best Practices

  1. Use copytruncate for applications that keep log files open.
  2. Set appropriate rotation frequency based on log volume.
  3. Configure compression to save disk space.
  4. Set retention based on compliance and storage requirements.
  5. Test configuration with dry run before applying.
  6. Monitor logrotate status regularly.
  7. Document log rotation policies for audit purposes.

Conclusion

This guide covered the complete process of installing Tomcat on three application servers and configuring logrotate for monthly rotation with three retained logs. The key steps were installing the packages, starting the service to generate logs, creating the logrotate configuration, and verifying the setup.

The copytruncate directive is essential for Tomcat because it keeps log files open while running. Without it, Tomcat would continue writing to the renamed log file, and the new log file would remain empty.

LogRotate is a powerful tool for managing log files efficiently. By configuring it properly, system administrators can ensure that log files do not consume excessive disk space while preserving historical data for troubleshooting and auditing.


Quick Reference

Task Command
Install Tomcat yum install -y tomcat
Start Tomcat systemctl start tomcat
Enable Tomcat systemctl enable tomcat
Install logrotate yum install -y logrotate
Create config vi /etc/logrotate.d/tomcat
Test config logrotate -d /etc/logrotate.d/tomcat
Check logs ls -la /var/log/tomcat/
Check status cat /var/lib/logrotate/logrotate.status

Configuration File Summary

/var/log/tomcat/*.log {
    monthly
    rotate 3
    compress
    missingok
    notifempty
    copytruncate
}
Enter fullscreen mode Exit fullscreen mode

This guide was created based on a real-world logrotate implementation on the Nautilus Application Servers in the Stratos Datacenter.

Top comments (1)