Configure the appender
-
In the Expert Editor, go to the directory of the container that emits your event, listed in How Logging Works. For
audit.*events that isxcc/backend/. -
Open
logback-audit.xml, or create it if it does not exist yet. -
Add the appender and the logger:
xcc/backend/logback-audit.xml
-
Set
syslogHostandportto your Syslog destination, andhostNameto the name your SIEM should show as the log source. Every parameter the appender accepts is under Available attributes. -
Set
logger nameto the event you chose. -
Set
patternto the format you chose.%jsonMsg%nabove is the default; the alternatives are in Format Converters. - For TCP or TLS instead of UDP, apply Use Syslog with TCP or TLS before publishing.
- Click Publish. The logging configuration becomes active within about one minute.
- Confirm the events arrive: Verify and Troubleshoot Logging.
For a Sandbox event, the file is
/etc/xorlab/dana/default/logback-audit.xml, which is not part of the Expert Editor. Edit it over SSH and restart the Sandbox stack instead of publishing, as described in Operation Reference.Use Syslog with TCP or TLS
UDP truncates messages at 1500 bytes. Use TCP for anything you rely on, and TLS whenever the logs leave your network, for example to a cloud-hosted SIEM.-
Set
protocoltoTCPor toSSLfor TLS. -
Wrap the Syslog appender in an
AsyncAppenderand reference that from the logger:xcc/backend/logback-audit.xml - Click Publish. The logging configuration becomes active within about one minute.
trustAll. If the TCP connection is dropped by an idle timeout on a firewall, see Keep a TCP connection alive.