after rotatoing the log ro prevent these timestamps: n22 ~ # ls -lt /var/log/snort/alert* -rw------- 1 snort snort 12697 Mar 18 19:38 /var/log/snort/alert.1 -rw------- 1 snort snort 0 Mar 17 21:20 /var/log/snort/alert -rw------- 1 snort snort 2229 Mar 16 21:23 /var/log/snort/alert.2 -rw------- 1 snort snort 3189 Mar 15 19:27 /var/log/snort/alert.3 -rw------- 1 snort snort 4622 Mar 14 19:35 /var/log/snort/alert.5 -rw------- 1 snort snort 0 Mar 13 19:40 /var/log/snort/alert.4 -rw------- 1 snort snort 1298 Mar 12 16:00 /var/log/snort/alert.7 Realized this while analysing non-working cron job for snortalog (the time stamp were tested to deside whether new entries have arrived or not)
or better, add asimilar line to the logrotate file : postrotate /bin/kill -HUP `cat /var/run/snort*.pid`
Hrm I somehow fail to find this file, which package does install that?
snortalog IIRC (in the meantime I unmerged that package, b/c BASE is better)
From which package the logrotate file comes?
tfoerste@n22 ~ $ equery --nocolor --quiet belongs /etc/logrotate.d/.keep app-admin/logrotate-3.7.1-r2 (/etc/logrotate.d/.keep)
(In reply to comment #5) > tfoerste@n22 ~ $ equery --nocolor --quiet belongs /etc/logrotate.d/.keep > app-admin/logrotate-3.7.1-r2 (/etc/logrotate.d/.keep) > I was talking about the logrotate file that rotate the snort logs
(In reply to comment #6) > (In reply to comment #5) > > tfoerste@n22 ~ $ equery --nocolor --quiet belongs /etc/logrotate.d/.keep > > app-admin/logrotate-3.7.1-r2 (/etc/logrotate.d/.keep) > > > > I was talking about the logrotate file that rotate the snort logs > As stated in https://bugs.gentoo.org/show_bug.cgi?id=126708#c3 it could come from net-analyzer/snortalog-2.4.0
I don't understand. If net-analyzer/snortalog don't provide the logrotate file, it is not a bug. You can create a attachment with le logrotate file if you want to be put in snort ebuild
Created attachment 102831 [details] logrotae.d - snort file I use this file.
As it is not a file that is provided by portage, there is no fix to do