These changes should keep snort and bro working together in ROCK. I've tested it on 3 production instances and it's held up for almost 2 weeks.
Create the dir for old snort logs
mkdir /data/snort/OLD
Add the snort_cleanup.sh (content below)
vim /usr/local/bin/snort_cleanup.sh
# Insert content
chmod +x /usr/local/bin/snort_cleanup.sh
Add a cron entry to run the cleanup
crontab -e
# Add the following:
#Snort Cleanup
58 * * * * /usr/local/bin/snort_cleanup.sh > /var/log/snort_cleanup.log 2>&1
Modify the snort config
Find the alert_unified2 output line and replace it with this:
output alert_unified2: filename snort.alert, limit 10
Restart snort
systemctl restart snortd
Move the old snort log
mv /data/snort/snort.alert /data/snort/OLD/