Skip to main content
Prerequisites
Syslog is the channel a SIEM or a log collector expects, and the one most deployments use. xorlab appears on the other side as a generic Syslog source, so no vendor app or connector is involved.

Configure the appender

  1. In the Expert Editor, go to the directory of the container that emits your event, listed in How Logging Works. For audit.* events that is xcc/backend/.
  2. Open logback-audit.xml, or create it if it does not exist yet.
  3. Add the appender and the logger:
    xcc/backend/logback-audit.xml
  4. Set syslogHost and port to your Syslog destination, and hostName to the name your SIEM should show as the log source. Every parameter the appender accepts is under Available attributes.
  5. Set logger name to the event you chose.
  6. Set pattern to the format you chose. %jsonMsg%n above is the default; the alternatives are in Format Converters.
  7. For TCP or TLS instead of UDP, apply Use Syslog with TCP or TLS before publishing.
  8. Click Publish. The logging configuration becomes active within about one minute.
  9. Confirm the events arrive: Verify and Troubleshoot Logging.
For a Sandbox event, the file is /etc/xorlab/dana/default/logback-audit.xml, which is not part of the Expert Editor. Edit it over SSH and restart the Sandbox stack instead of publishing, as described in Operation Reference.
Repeat step 1 for each container that emits an event you want. A login audit trail, for example, needs the same appender in auth/auth/ as well, because audit.access.* is emitted by Auth and not by Backend.

Use Syslog with TCP or TLS

UDP truncates messages at 1500 bytes. Use TCP for anything you rely on, and TLS whenever the logs leave your network, for example to a cloud-hosted SIEM.
  1. Set protocol to TCP or to SSL for TLS.
  2. Wrap the Syslog appender in an AsyncAppender and reference that from the logger:
    xcc/backend/logback-audit.xml
  3. Click Publish. The logging configuration becomes active within about one minute.
The AsyncAppender is mandatory for TCP and TLSWithout it, a slow or unreachable destination blocks the component that is writing the log, and xorlab might not work properly.
For an unsigned certificate on the receiving side, add trustAll. If the TCP connection is dropped by an idle timeout on a firewall, see Keep a TCP connection alive.

Available attributes

Where to configure the receiving side

The work on the other end is your platform’s standard “add a Syslog source” procedure. Connect a SIEM links the vendor documentation for Splunk, Microsoft Sentinel, QRadar, Elastic, Graylog, and others.