Deployment Architecture

What does Splunk log "rollout" refer to?

nagarjuna280
Communicator

I heard the word "rollout" regarding /opt/splunk/var/log/splunk files

Tags (1)
0 Karma

somesoni2
Revered Legend

The rotation of Splunk internal logs files, available in $SPLUNK_HOME/var/log/splunk folder, is managed by log.cfg file. The by default they roll to a new file when the log file size reaches 25MB (specified in bytes) and 5 backup/rolledover files are retained. See below links for more details:

https://docs.splunk.com/Documentation/Splunk/6.5.0/Troubleshooting/WhatSplunklogsaboutitself
https://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Enabledebuglogging#In_log.cfg

0 Karma

ddrillic
Ultra Champion

What do you really mean?

Get Updates on the Splunk Community!

What's New in Splunk Observability - October 2025

What’s New?  We’re excited to announce the latest enhancements to Splunk Observability Cloud and share what’s ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened Audit Trail v2 wasn’t written in isolation—it was shaped by your voices. In ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...