> Okay, confirmed eve-log outputs appear to rotate fine, so switched
> over to only those for now. Below is the current suri config I'm
> testing.

I found a very similar thing when I forgot to HUP suricata.

I'm just wondering, perhaps su-ing to suri/suri means it's not HUPping the process for some reason.

If you run the HUP postrotate line manually as root after doing a logrotate (you'll have to put the "create" line back in), does it start writing to the new files	?


