# Cis Tomcat8 V100 7.7

> Configure log file size limit (Scored)

- Skill: `cyberstrikeus/cis-tomcat8-v100-7-7` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-tomcat8-v100-7-7`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-tomcat8-v100-7-7/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-tomcat8-v100-7-7

---


# 7.7 Configure log file size limit (Scored)

## Description

Tomcat logging can be configured to limit the size of log files. Proper log file management helps prevent disk space exhaustion and ensures log data is rotated appropriately.

## Rationale

Without proper log rotation and size limits, log files can grow indefinitely, consuming disk space and potentially causing denial of service conditions. Configuring log file size limits ensures that logs are managed properly.

## Audit Procedure

Review the `$CATALINA_HOME/conf/logging.properties` file to verify that the `maxDays` attribute is configured for each handler:

```bash
$ grep "maxDays" $CATALINA_HOME/conf/logging.properties
```

Verify that the `maxDays` property is set to an appropriate value (e.g., 90 days or less).

## Remediation

Edit the `$CATALINA_HOME/conf/logging.properties` file and add or modify the `maxDays` attribute for each file handler:

```properties
1catalina.org.apache.juli.AsyncFileHandler.maxDays = 90
2localhost.org.apache.juli.AsyncFileHandler.maxDays = 90
3manager.org.apache.juli.AsyncFileHandler.maxDays = 90
4host-manager.org.apache.juli.AsyncFileHandler.maxDays = 90
```

## Default Value

By default, `maxDays` is not set, meaning log files are not automatically removed.

## References

1. https://tomcat.apache.org/tomcat-8.0-doc/logging.html
2. https://tomcat.apache.org/tomcat-8.0-doc/api/org/apache/juli/FileHandler.html

## CIS Controls

**v7:**

- 6.4 Ensure adequate storage for logs
  - Ensure that all systems that store logs have adequate storage space for the logs generated.

## Profile Applicability

- Level 1

