Skip to main content
Prerequisites
This channel sends one mail every time the event occurs. That suits an event a person has to act on, such as a release request waiting for approval or a failed backup, and does not suit anything that happens more than a few times a day.
This is not the notification system your end users see. Quarantine digests, banners, and release notifications are templates, configured under Notifications Overview.

Configure the appender

  1. In the Expert Editor, go to the directory of the container that emits your event, listed in How Logging Works.
  2. Open logback-audit.xml, or create it if it does not exist yet.
  3. Add the appender and the logger. The mail is relayed differently depending on which component sends it, so pick the tab that matches your event’s container:
    Relays through the local MTA on its internal port, so no TLS is involved.
    activeguard/core/logback-audit.xml
  4. Set host.name to the domain of your xorlab, and smtpHost accordingly.
  5. Set to, subject and pattern to the recipient and the message body you want. %d is the timestamp, %jsonMsg the whole event, and %logArg{key} a single field from it. The full list is in Format Converters.
  6. Set logger name to the event you chose.
  7. Click Publish. The logging configuration becomes active within about one minute.
  8. Trigger the event once and confirm the mail arrives: Verify and Troubleshoot Logging.
Attach this appender only to an event you know is rare. A logger name that is a prefix, audit rather than audit.quarantine.release.request.created, turns every analyst click into an email.

Common use: approve release requests by mail

The Backend example above logs audit.quarantine.release.request.created, which is the event behind the Self-Service Quarantine release workflow. The approver gets a mail with a direct link to the message instead of having to watch a queue in XCC. See Enable Release Requests for the rest of that setup.