AppSuite:Log forwarding: Difference between revisions
From Open-Xchange
No edit summary |
(→HTTP) |
||
Line 120: | Line 120: | ||
* openexchange.login.client – login client | * openexchange.login.client – login client | ||
* openexchange.login.login – login username | * openexchange.login.login – login username | ||
* login | |||
* fields | |||
* Login – username | |||
* IP – client ip | |||
* AuthID – auth id | |||
* Agent – user Agent | |||
* Client – login client | |||
* Context – internal context id | |||
* User – internal user id in context | |||
* Session – session Id | |||
* Random – random | |||
* openexchange.grizzly.remoteAddress – client ip | |||
* openexchange.grizzly.serverName – hostname | |||
* openexchange.grizzly.userAgent – User | |||
* openexchange.login.client – login client | |||
* openexchange.login.login – login username | |||
* logout | * logout | ||
* fields | |||
* Logout – fixed word | * Logout – fixed word | ||
* Context – internal context id | * Context – internal context id |
Revision as of 10:46, 11 September 2019
Log Forwarding
Open-Xchange Logs
- Log items are in plain ASCII line-based format, with data usually in
- name=value format (no whitespace in values), space-separated.
- Non-printable ASCII will be escaped to preserve log integrity
- Dates are output in the format: YYYY-MMDDTHH:MM:SS.mmm+hh:mm (+hh:mm should be expected as 00:00 as systems running with UTC)
- events and fields in bold should be available with the log delivery workaround (AppSuite logs) all the fields should be available with the log delivery final solution (Dovecot logs)
IMAP
events * failed login * fields * reason for failed login * user – login username * method – authentication method * rip – remote client ip * TLS – if connection was using tls * session – uniqe session id * succesful login * fields * user – login username * method – authentication method * rip – remote client ip * lport – local port connected to * TLS – if connection was using tls * session – unique session id * logout * fields * disconnect reason * in – bytes received * out – bytes send * user – login username * method – authentication method * rip – remote client ip * lport – local port connected to * TLS – if connection was using tls * session – uniqe session id
POP3
events * failed login * fields * reason for failed login * user – login username * method – authentication method * rip – remote client ip * TLS – if connection was using tls * session – uniqe session id * successful login * fields * user – login username * method – authentication method * rip – remote client ip * TLS – if connection was using tls * session – unique session id * logout * fields * disconnect reason * in – bytes received * out – bytes sent * user – login username * method – authentication method * rip – remote ip * TLS – if connection was using tls * session – unique session id
SMTP
events * failed login * fields * disconnect reason * user – login username * method – authentication method * rip – remote ip * TLS – if connection was using tls * session – unique session id * login * fields * user – login username * method – authentication method * rip – remote ip * TLS – if connection was using tls * session – unique session id * mail sent * fields * queue ID * message-id * from – envelope from * size * nrcpt – number of recipients * to – recipient * relay – receiving server * status – status of message * remote answer * delays * remove – when message was removed from queue * logout * fields * disconnect reason * in – bytes received * out – bytes sent * user – login username * method – authentication method * rip – remote ip * TLS – if connection was using tls * session – unique session id
HTTP
events * failed login * fields * failed reason * openexchange.grizzly.remoteAddress – client ip * openexchange.grizzly.serverName – hostname * openexchange.grizzly.userAgent – User * openexchange.login.client – login client * openexchange.login.login – login username * login * fields * Login – username * IP – client ip * AuthID – auth id * Agent – user Agent * Client – login client * Context – internal context id * User – internal user id in context * Session – session Id * Random – random * openexchange.grizzly.remoteAddress – client ip * openexchange.grizzly.serverName – hostname * openexchange.grizzly.userAgent – User * openexchange.login.client – login client * openexchange.login.login – login username * logout * fields * Logout – fixed word * Context – internal context id * User – internal user id * Session – session id * openexchange.grizzly.remoteAddress – client ip * openexchange.grizzly.serverName – hostname * openexchange.grizzly.userAgent – User