pattern inside the encoder of an appender, so the same choice applies to Syslog, email, and file appenders alike:
Always end a pattern with
%n, the line break. Without it, records run into each other.
Converters
JSON
The most common choice on xorlab, and the default in every guide. It records the attributes of the event itself, as one JSON object per record.JSON extended
Only for Message-tracing events, numbered 1000 to 1999. Instead of the attributes of that one event, it records the whole result of the email analysis as a single entry: verdict, scores, tags, participants, attachments with hashes, and extracted indicators.Example JSON
Example JSON
trace.msg_released does not support the email result extension, so a release from quarantine is recorded without the analysis result.
Parameters
Extended JSON takes parameters in curly brackets,%coreJsonMsg{param1,param2,param3,...}, to control the subject and to add email headers:
The following pattern leaves the subject out and always adds the
message-id and x-custom-header headers, which is a common requirement where the subject line is treated as personal data:
ON_DROP_BOUNCE_AND_QUARANTINE is the middle ground: the subject is recorded only for mail that was dropped, bounced, or quarantined. See also Change Storing of Subject.
Specific attributes
%logArg{} records named key-value pairs instead of the whole event. It works for any event, in any appender, on every component. To find the key names, configure the appender with %jsonMsg%n first, look at one record, then narrow it down.
Common Event Format (CEF)
CEF is what ArcSight-style platforms and CEF data connectors expect. Select it with%cef: