Splunk SOAR (f.k.a. Phantom)

What is the best practice to rotate the /var/log/phantom/app_interface.log file

Nadear
New Member

Hi everyone,

I have limited disk space on /var/log path, so I try to manage phantom log rotation ( follow this link: Configure the logging levels for Splunk SOAR (On-premises) daemons - Splunk Documentation)

but I found a large file named "app_interface.log" that was not included in phantom_logrotate.conf

Does anyone have any suggestions on what kind of records are collected in this file? and What is the best practice to rotate this file?

Thank you

 

Labels (2)
0 Karma

phantom_mhike
SplunkTrust
SplunkTrust

There is a lot of context here for some app operations like widget generation but its not terribly useful beyond the scope of debugging an app issue. I would suggest adding it to the logrotate conf and setting it to roll daily. I wouldn't personally keep more than 7 days. Really if you are debugging an app, historical records are much less useful that active debugging. 

0 Karma
Get Updates on the Splunk Community!

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...