Splunk SOAR

What is the best practice to rotate the /var/log/phantom/app_interface.log file

Nadear
New Member

Hi everyone,

I have limited disk space on /var/log path, so I try to manage phantom log rotation ( follow this link: Configure the logging levels for Splunk SOAR (On-premises) daemons - Splunk Documentation)

but I found a large file named "app_interface.log" that was not included in phantom_logrotate.conf

Does anyone have any suggestions on what kind of records are collected in this file? and What is the best practice to rotate this file?

Thank you

 

Labels (2)
0 Karma

phantom_mhike
SplunkTrust
SplunkTrust

There is a lot of context here for some app operations like widget generation but its not terribly useful beyond the scope of debugging an app issue. I would suggest adding it to the logrotate conf and setting it to roll daily. I wouldn't personally keep more than 7 days. Really if you are debugging an app, historical records are much less useful that active debugging. 

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...