Skip to main content
Every example below is a whole file. Paste it into the directory it names, change the destination, and click Publish — the logging configuration becomes active within about one minute. Then confirm it works with Verify and Troubleshoot Logging. If a file already exists in that directory, merge the appender and logger elements into it rather than replacing it. A new logger can reference an appender that is already in the file, so there is no need for a second one.

Log detailed email results

One record per email carrying the complete analysis result, sent to a remote Syslog server. This is the configuration most SIEM projects start from.
activeguard/core/logback-audit.xml
Extended JSON records exceed the 1500-byte UDP limit and are truncated. For this example in particular, switch to TCP or TLS.

Log audit events

Every action an analyst or admin takes in XCC, in JSON, to a remote Syslog server. The logger name is the prefix audit, so it covers all of the sub-categories.
xcc/backend/logback-audit.xml
Logins are missing from this oneSuccessful and failed logins are emitted by the Auth container, not by Backend. Put the same file in auth/auth/ as well to capture audit.access.*.

Log SMTP email traces

One JSON record when an email is accepted over SMTP, and another for each delivery attempt. This is the mail flow view, for checking whether an email reached xorlab and whether xorlab handed it on.
activeguard/mta/audit/logback-audit.xml
How to log all SMTP logsTo forward the complete SMTP log rather than the accept and relay events only, replace the name of the first logger with trace.mta and remove the second logger. That is the whole Postfix activity log, so check the volume first.

Correlate the queue ID with the GGRID

The two events above carry the SMTP queue ID. To join it to the email’s GGRID, the identifier used by XCC and the analysis, add this event on the Core container as well.
activeguard/core/logback-audit.xml

Log detailed email results per verdict

A record every time a verdict is reached, rather than once per email. The case this exists for:
  • An email looks legitimate and is delivered, but
  • a delayed or offline Sandbox scan later changes the verdict from benign to malicious.
You then get two records for the same email, one per verdict, so the change of status is visible in the SIEM instead of being overwritten.
activeguard/core/logback-audit.xml

Log threat intelligence

One JSON record per malicious domain observed in your own mail, written to a local file and sent over Syslog. It is also the example to copy for sending any event to two destinations at once, and the only one here that needs additivity.
On-premises onlyWriting to local files is only supported for xorlab on-premises. On a hosted deployment, keep the Syslog appender and drop the file appender.
xcc/backend/logback-audit.xml
For the other indicator types, add a logger for ti.email, ti.ip, ti.file, and ti.url referencing the same appenders — or use the prefix ti for all of them. What each one carries is in Connect a SIEM.