# Percona mysql 8.4 audit log filter component log rotation using logrotate

**URL:** <https://forums.percona.com/t/percona-mysql-8-4-audit-log-filter-component-log-rotation-using-logrotate/38896>\
**Category:** Other MySQL® Questions\
**Created:** [July 31, 2025, 1:36am UTC](https://forums.percona.com/t/percona-mysql-8-4-audit-log-filter-component-log-rotation-using-logrotate/38896 "2025-07-31T01:36:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charly\_Wu](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/charly_wu/32/16997_2.png) [@Charly\_Wu](https://forums.percona.com/u/Charly_Wu)\
**Post date:** [July 31, 2025, 1:36am UTC](https://forums.percona.com/t/percona-mysql-8-4-audit-log-filter-component-log-rotation-using-logrotate/38896/1 "2025-07-31T01:36:03Z")

</div>

Hi,

I would like to use logrotate to perform log rotation of audit log generated by Percona’s audit log filter component (MySQL 8.4).

when the format is set to JSON, I notice the file begins with ‘[‘ which indicate that the whole file will be a JSON array.

any recommendations?

---

<div class="post-metadata">

**Author:** ![kedarpercona](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/kedarpercona/32/809_2.png) [@kedarpercona](https://forums.percona.com/u/kedarpercona)\
**Post date:** [July 31, 2025, 5:35am UTC](https://forums.percona.com/t/percona-mysql-8-4-audit-log-filter-component-log-rotation-using-logrotate/38896/2 "2025-07-31T05:35:43Z")

</div>

Hi @Charly_Wu and welcome back to Percona community.

You might want to use the inbuild configuration for the rotation: [audit\_log\_rotate\_on\_size](https://docs.percona.com/percona-server/8.0/audit-log-plugin.html#audit_log_rotate_on_size), audit\_log\_rotations.

You have dedicated section in documentation for audit log rotation:

> **[MySQL :: MySQL 8.4 Reference Manual :: 8.4.5.5 Configuring Audit Logging...](https://dev.mysql.com/doc/refman/8.4/en/audit-log-logging-configuration.html#audit-log-automatic-rotation)**

Thanks,

Kedar

---

<div class="post-metadata">

**Author:** ![sbstnpl](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/sbstnpl/32/2789_2.png) [@sbstnpl](https://forums.percona.com/u/sbstnpl)\
**Post date:** [August 1, 2025, 6:34am UTC](https://forums.percona.com/t/percona-mysql-8-4-audit-log-filter-component-log-rotation-using-logrotate/38896/3 "2025-08-01T06:34:15Z")

</div>

Hi @Charly_Wu ,

we’ve moved away from logrotate and simply do this with a nightly cron job;  
`SELECT audit_log_rotate();`

I recommend to have an own user for this, just granted with AUDIT\_ADMIN permissions.

Alternatively, you could even execute this from a scheduled event:  
`CREATE EVENT IF NOT EXISTS audit_log_rotate_nightly ON SCHEDULE EVERY 1 DAY STARTS ‘2025-07-31 00:00:00’ COMMENT ‘daily audit-log rotation’ DO SELECT audit_log_rotate();`

Sebastian
