===comet_backup=== /var/log/comet_backup.log { daily rotate 14 compress delaycompress missingok notifempty create 0640 root root } ===comet_backup_jobs_helper=== /var/log/comet_backup_jobs_helper.log { daily rotate 14 compress delaycompress missingok notifempty copytruncate # make sure backup jobs can continue to write to the same file through a rotation create 0640 root root } ===ea-php82-php-fpm=== /opt/cpanel/ea-php82/root/var/log/php-fpm/*log { missingok notifempty sharedscripts delaycompress postrotate /bin/kill -SIGUSR1 `cat /opt/cpanel/ea-php82/root/var/run/php-fpm/php-fpm.pid 2>/dev/null` 2>/dev/null || true endscript } ===apache=== cat: /etc/logrotate.d/apache: Permission denied ===lfd=== /var/log/lfd.log { weekly rotate 1 compress missingok } /var/log/lfd_messenger.log { weekly rotate 1 compress missingok } ===imunify-core=== # DEF-26794: agent log rotation, replacing the in-process # RotatingCompressionFileHandler. # # Uses copytruncate so the agent's open fd remains valid across rotation # (same inode, just truncated) — no postrotate signal needed and no risk # of the agent writing into a renamed/deleted file. The brief copy↔truncate # window may drop a handful of bytes under heavy logging; acceptable for # debug logs. # # Shipped by imunify-core because the agent code (defence360agent) that # writes these files is shipped by imunify-core; this keeps the rotation # config co-located with the writer for both Imunify360 and ImunifyAV # installations. # # error.log is intentionally NOT listed here: the Go resident agent # (src/resident-agent/errorlog.go) owns rotation for that file with its # own size-based rename chain. Letting logrotate also touch error.log # means two writers compete on error.log.{1,2,...}.gz, and the Go agent's # next rotate() copyFile(error.log, error.log.1) would clobber an # uncompressed archive that logrotate had just produced under # `delaycompress`. /var/log/imunify360/network.log /var/log/imunify360/debug.log /var/log/imunify360/console.log /var/log/imunify360/hook.log /var/log/imunify360/process_message.log /var/log/imunify360/acronis-installer.log /var/log/imunify360_user_logs/*/*.log { # Non-root invocations (e.g. CageFS user contexts) route logs to a # per-user directory; the previous in-process handler enforced size # limits there too, so cover them with the same policy. The Go resident # agent only runs as root and never writes to these paths, so no # dual-rotation conflict applies — `error.log` is safe to include here. daily maxsize 60M rotate 5 # Drop archives older than 30 days regardless of position. This also # eventually purges leftovers from the old in-process rotation # (console.log.6.gz, console.log.7.gz, ...) that the fixed rename # chain never touched. maxage 30 missingok notifempty compress delaycompress copytruncate }