Splunk SOAR (f.k.a. Phantom)

What is the best practice to rotate the /var/log/phantom/app_interface.log file

Nadear
New Member

Hi everyone,

I have limited disk space on /var/log path, so I try to manage phantom log rotation ( follow this link: Configure the logging levels for Splunk SOAR (On-premises) daemons - Splunk Documentation)

but I found a large file named "app_interface.log" that was not included in phantom_logrotate.conf

Does anyone have any suggestions on what kind of records are collected in this file? and What is the best practice to rotate this file?

Thank you

 

Labels (2)
0 Karma

phantom_mhike
SplunkTrust
SplunkTrust

There is a lot of context here for some app operations like widget generation but its not terribly useful beyond the scope of debugging an app issue. I would suggest adding it to the logrotate conf and setting it to roll daily. I wouldn't personally keep more than 7 days. Really if you are debugging an app, historical records are much less useful that active debugging. 

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...