Rotating logs without losing lines
30 September 2026Logrotate has two ways to deal with a program that keeps its log file open. The default way renames the file and then asks the program to reopen it. The other way, copytruncate, copies the file and empties the original in place.
The second option is tempting because it needs no cooperation from the program, but there is a short gap between the copy and the truncate. Lines written in that gap are lost. On a busy service that is not a theoretical problem.
If the service can reopen its logs on a signal, use that instead:
/var/log/myapp/*.log {
weekly
rotate 8
compress
delaycompress
postrotate
systemctl reload myapp.service
endscript
}
delaycompress leaves the newest rotated file uncompressed for one more cycle, which helps when the program is still flushing to it. Test a new rule with logrotate -d /etc/logrotate.d/myapp before trusting it.