Three decisions
Every logging configuration is the same three decisions, whichever channel you use:Steps
Configuration Examples
Complete, copy-ready configuration files for the most common goals. Start here if you already know which event you want.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Which xorlab events can leave the platform, the three channels that carry them, and the order to work through the decisions.
| Decision | Example |
|---|---|
| Which event should be recorded, and therefore which component’s configuration file you edit | trace.msg_analysis.complete, in activeguard/core/ |
| Which channel carries it | Syslog, email, or a log file |
| Which format the payload uses | JSON, extended JSON, or CEF |
| Step | Description |
|---|---|
| How Logging Works | Recommended. Explanation of loggers, appenders, and why the configuration is split across components. |
| Choose What to Log | Mandatory. Pick the events and the payload format for what you want to achieve. |
| Forward Events over Syslog | Optional. Send events to a SIEM, a log collector, or any Syslog listener. |
| Send an Email When an Event Occurs | Optional. Get a mail for a low-volume event, such as a quarantine release request. |
| Write Events to a Log File | Optional. Write events to a rolling file on the xorlab host. On-premises deployments only. |
| Verify and Troubleshoot Logging | Mandatory. Confirm the events arrive, and work out why they do not. |