LINUXOR.SK ... open source notes ...

Vault - auditd-logrotate (cron.daily script)

category: solutionz · date: 2024-12-31 · updated: 2026-10-02 · author: LALA

Vault Solution · Config document · referenced from Audit logging and log shipping

The Linux audit daemon rotates its log by size, not by time, and logrotate must not touch it. This daily script makes it rotate once a day, stamps and compresses the rotated files and keeps fourteen of them, so the audit log follows the same policy as every other log. max_log_file_action = ignore in /etc/audit/auditd.conf switches the size-based rotation off.

ItemValue
Path on the host/etc/cron.daily/auditd-logrotate
Modeexecutable
Deployed onevery server
Based onRed Hat solution 661603

The file

bash
#!/bin/bash
#
# REF: https://access.redhat.com/solutionz/661603
#

export PATH=/sbin:/bin:/usr/sbin:/usr/bin

FORMAT="%Y%m%d" # Customize timestamp format as desired, per `man date`
                # %F_%T will lead to files like: audit.log.2015-02-26_15:43:46
COMPRESS=gzip   # Change to bzip2 or xz as desired
KEEP=14         # Number of compressed log files to keep
ROTATE_TIME=5   # Amount of time in seconds to wait for auditd to rotate its logs. Adjust this as necessary

rename_and_compress_old_logs() {
    for file in $(find /var/log/audit/ -name 'audit.log.[0-9]'); do
        timestamp=$(ls -l --time-style="+${FORMAT}" ${file} | awk '{print $6}')
        newfile=${file%.[0-9]}.${timestamp}
        # Optional: remove "-v" verbose flag from next 2 lines to hide output
        mv -v ${file} ${newfile}
        ${COMPRESS} -v ${newfile}
    done
}

delete_old_compressed_logs() {
    # Optional: remove "-v" verbose flag to hide output
    rm -v $(find /var/log/audit/ -regextype posix-extended -regex '.*audit\.log\..*(xz|gz|bz2)$' | sort -n | head -n -${KEEP})
}

rename_and_compress_old_logs
service auditd rotate
sleep $ROTATE_TIME
rename_and_compress_old_logs
delete_old_compressed_logs
← solutionz