Splunk SOAR

What is the best practice to rotate the /var/log/phantom/app_interface.log file

Nadear
New Member

Hi everyone,

I have limited disk space on /var/log path, so I try to manage phantom log rotation ( follow this link: Configure the logging levels for Splunk SOAR (On-premises) daemons - Splunk Documentation)

but I found a large file named "app_interface.log" that was not included in phantom_logrotate.conf

Does anyone have any suggestions on what kind of records are collected in this file? and What is the best practice to rotate this file?

Thank you

 

Labels (2)
0 Karma

phantom_mhike
SplunkTrust
SplunkTrust

There is a lot of context here for some app operations like widget generation but its not terribly useful beyond the scope of debugging an app issue. I would suggest adding it to the logrotate conf and setting it to roll daily. I wouldn't personally keep more than 7 days. Really if you are debugging an app, historical records are much less useful that active debugging. 

0 Karma
Get Updates on the Splunk Community!

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...