How to reduce Linux audit log rotation frequency?

Server Administration

A server administrator notices the /var/log/audit/audit.log file on a Linux server is rotating too frequently. The administrator would like to decrease the number of times the log rotates without losing any of the information in the logs. Which of the following should the administrator configure?

  1. Increase the audit.log file size in the appropriate configuration file. Source Reference Answer
  2. Decrease the duration of the log rotate cycle for the audit.log file.
  3. Remove the log rotate directive from the audit.log file configuration.
  4. Move the audit.log files to a remote syslog server.

Community Votes

A
62%
B
38%

62% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests understanding of logrotate parameters; the trap is confusing 'decreasing duration' with 'decreasing frequency', where shorter durations actually cause more frequent rotations.

To decrease the frequency of /var/log/audit/audit.log rotation without data loss, increase the maximum file size threshold in the logrotate configuration. Community consensus identifies increasing the file size as the correct method to delay rotation triggers.

Option B is chosen by some who misread 'decrease frequency' as 'decrease the time interval', not realizing that a shorter interval results in more frequent rotations.

Community Discussion (3 comments)

SecNoob27639 👍 3 Selected: A
B is the exact OPPOSITE of what is being requested. By decreasing the duration of the rotate cycle, you will end up creating more logs. C would just stop creating additional logs, defeating the purpose of log rotation. D doesn't change the fact that logs are being created too frequently, it just puts them somewhere else. So the only viable answer is A - increase the audit.log file size in the appropriate configuration file.
tame_rabbit 👍 2 Selected: A
Increasing the file size limit for the audit.log file would delay log rotation until the file reaches the specified size. This can be a valid solution if the issue is that the file is rotating too frequently due to reaching its size limit quickly.
surfuganda 👍 3 Selected: B
B. To decrease the frequency of log rotation for the /var/log/audit/audit.log file without losing any information in the logs, the server administrator should decrease the duration of the log rotate cycle. This can be achieved by adjusting the logrotate configuration for the audit log files to specify a longer time interval or a larger file size threshold before rotation occurs.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Increasing the maximum size of the log file (Option A) delays the point at which the log rotates. If the file grows slower than the new larger limit, it will rotate less often, satisfying the requirement to decrease frequency without losing data.

Why the Other Options Are Wrong

Decreasing the duration (Option B) would trigger rotations more frequently, which is the opposite of the goal. Removing rotation (Option C) risks filling the disk and losing older logs if not managed. Moving logs (Option D) does not change the local rotation frequency or prevent the issue on the source server.

Community Comment Notes

Comment [1] correctly notes that Option B is the exact opposite of the request. Comment [3] supports Option A by explaining that increasing the size limit delays rotation until the file reaches that specified size.

Exam Strategy

Always read 'decrease frequency' carefully; it means you want fewer events over time, not shorter intervals. When troubleshooting log rotation, consider both size-based and time-based triggers and how changing them affects the total count.

Related Analysis

Practice All SK0-005 Questions

Access 135 questions with complete answers and detailed explanations.

View Full SK0-005 Practice Test →

← Back to SK0-005 Study Guide