Splunk SOAR

What is the best practice to rotate the /var/log/phantom/app_interface.log file

Nadear
New Member

Hi everyone,

I have limited disk space on /var/log path, so I try to manage phantom log rotation ( follow this link: Configure the logging levels for Splunk SOAR (On-premises) daemons - Splunk Documentation)

but I found a large file named "app_interface.log" that was not included in phantom_logrotate.conf

Does anyone have any suggestions on what kind of records are collected in this file? and What is the best practice to rotate this file?

Thank you

 

Labels (1)
0 Karma

phantom_mhike
SplunkTrust
SplunkTrust

There is a lot of context here for some app operations like widget generation but its not terribly useful beyond the scope of debugging an app issue. I would suggest adding it to the logrotate conf and setting it to roll daily. I wouldn't personally keep more than 7 days. Really if you are debugging an app, historical records are much less useful that active debugging. 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...