Skip to main content
The shape of a record is set by the pattern inside the encoder of an appender, so the same choice applies to Syslog, email, and file appenders alike:
Always end a pattern with %n, the line break. Without it, records run into each other.

Converters

JSON

The most common choice on xorlab, and the default in every guide. It records the attributes of the event itself, as one JSON object per record.

JSON extended

Only for Message-tracing events, numbered 1000 to 1999. Instead of the attributes of that one event, it records the whole result of the email analysis as a single entry: verdict, scores, tags, participants, attachments with hashes, and extracted indicators.
A record like the one above is well over the 1500-byte limit that UDP Syslog truncates at. Use TCP or TLS with this converter.
One exception is worth knowing: trace.msg_released does not support the email result extension, so a release from quarantine is recorded without the analysis result.

Parameters

Extended JSON takes parameters in curly brackets, %coreJsonMsg{param1,param2,param3,...}, to control the subject and to add email headers: The following pattern leaves the subject out and always adds the message-id and x-custom-header headers, which is a common requirement where the subject line is treated as personal data:
ON_DROP_BOUNCE_AND_QUARANTINE is the middle ground: the subject is recorded only for mail that was dropped, bounced, or quarantined. See also Change Storing of Subject.

Specific attributes

%logArg{} records named key-value pairs instead of the whole event. It works for any event, in any appender, on every component. To find the key names, configure the appender with %jsonMsg%n first, look at one record, then narrow it down.
This is also how you build a readable email body out of a single event. See Send an Email When an Event Occurs.

Common Event Format (CEF)

CEF is what ArcSight-style platforms and CEF data connectors expect. Select it with %cef:
A CEF record starts with static properties, the event ID and name among them, followed by the event-specific payload:
The static properties, present on every event:

Additional converters

A pattern is not limited to one converter. Every standard Logback converter can be combined with the ones above — see the table under Pattern Layout for the full list. For example, this prefixes the CEF payload with a date: