I think in 10.4 it's splunk/etc/log-node-platform.cfg Log rotation settings (max file size, backup count, max age, compression) are inherited from the parent sidecar's stanza in log-node-platform.cfg . If no sidecar-specific stanza exists, the [global] stanza is used. If no config exists at all, defaults apply (50MB, 15 backups, 28 days, gz). For <10.4, sorry think it might not be configurable. It's normally the spotlight/spotlight_metrics-2026*.json that goes 2 X 500MB + 1 new.
... View more