Skip to main content
Prerequisites
This is separate from the log files xorlab writes anyway — those are described in Built-in Log Files and need no configuration.

Configure the appender

  1. In the Expert Editor, go to the directory of the container that emits your event, listed in How Logging Works.
  2. Open logback-audit.xml, or create it if it does not exist yet.
  3. Add the appender and the logger:
    xcc/backend/logback-audit.xml
  4. Set file and fileNamePattern to the file name you want. ${log_dir} resolves to that component’s own log directory on the host, under /var/log/xorlab/ — see Operation Reference.
  5. Set the rolling policy. maxFileSize caps one file, maxHistory the number of rolled files kept, and totalSizeCap the compressed total. Set a bound you can afford. A file appender on a per-email event fills a disk quickly, and nothing else on the host trims it for you.
  6. Set logger name to the event you chose.
  7. Set pattern to the format you chose. The alternatives are in Format Converters.
  8. Click Publish. The logging configuration becomes active within about one minute.
  9. Trigger the event and confirm the file appears: Verify and Troubleshoot Logging.
One event can go to a file and to a SIEM at once — declare both appenders and reference both from the same logger. There is a worked example in Log threat intelligence.