If a file already exists in that directory, merge the
appender and logger elements into it rather than replacing it. A new logger can reference an appender that is already in the file, so there is no need for a second one.
Log detailed email results
One record per email carrying the complete analysis result, sent to a remote Syslog server. This is the configuration most SIEM projects start from.activeguard/core/logback-audit.xml
Log audit events
Every action an analyst or admin takes in XCC, in JSON, to a remote Syslog server. The logger name is the prefixaudit, so it covers all of the sub-categories.
xcc/backend/logback-audit.xml
Log SMTP email traces
One JSON record when an email is accepted over SMTP, and another for each delivery attempt. This is the mail flow view, for checking whether an email reached xorlab and whether xorlab handed it on.activeguard/mta/audit/logback-audit.xml
Correlate the queue ID with the GGRID
The two events above carry the SMTP queue ID. To join it to the email’s GGRID, the identifier used by XCC and the analysis, add this event on theCore container as well.
activeguard/core/logback-audit.xml
Log detailed email results per verdict
A record every time a verdict is reached, rather than once per email. The case this exists for:- An email looks legitimate and is delivered, but
- a delayed or offline Sandbox scan later changes the verdict from benign to malicious.
activeguard/core/logback-audit.xml
Log threat intelligence
One JSON record per malicious domain observed in your own mail, written to a local file and sent over Syslog. It is also the example to copy for sending any event to two destinations at once, and the only one here that needsadditivity.
xcc/backend/logback-audit.xml
ti.email, ti.ip, ti.file, and ti.url referencing the same appenders — or use the prefix ti for all of them. What each one carries is in Connect a SIEM.