Is it normal that windows server 2003 ICF, just deletes all the entries in the log when it reaches the size limit set and starts over.

This just seems like bad design doesnt it? I remember awhile ago i read somewhere that it renames the pfirewall.log to pfirewall1.log or something close to that and then starts the new log, but i tried it and it just deleted the old entries and started a new blank one and didnt keep anything. So if someone floods the connection with whatever packets after the attack it will erase the firewall logs. Am i making sense?

Please let me know if im missing something about this