Skip to main content
xorlab writes its own local log files without any configuration. Everything beyond that is opt-in: no event is sent anywhere until you name it in a logging configuration file.
Connecting a SIEM?Start with Connect a SIEM. It covers which events are worth forwarding, which payload format to pick, and where to look in the documentation of Splunk, Microsoft Sentinel, QRadar, Elastic, and others — then sends you back here for the configuration.

Three decisions

Every logging configuration is the same three decisions, whichever channel you use:

Steps

Configuration Examples

Complete, copy-ready configuration files for the most common goals. Start here if you already know which event you want.

What xorlab logs without any configuration

Each component writes an audit log, an error log, and a verbose operational log to the local filesystem, rotated and size-capped. Those files exist whether or not you configure anything in this group. For on-premises deployments, Built-in Log Files explains how to configure the built-in logs and Operation Reference shows where they are located.