Managing server logs
The following are the types of server logs:
|
Log type |
What is logged? |
|---|---|
| System logs |
System-related information |
| Audit logs |
User activity |
| Rule-triggered logs |
Rules in which users have specified the Make new <log entry> action. For more information about the <log entry> action, see Actions and stop actions. |
These are used to log the usage of the system. These logs are available in XProtect Management Client under Server Logs.
For information about logs used for troubleshooting and investigating software errors, see Debug logs .
Search and filter logs
VictoriaLogs supports various types of filters in LogsQL for querying logs. Here are the main filter types and their uses:
-
General filters. You can select or exclude log records based on field values, time, words, phrases, and stream information.
-
Multiple field search. You can search over multiple fields simultaneously to match records for multiple filter conditions.
-
Time filter. Use to restrict queries to specific time windows.
-
Day or week range filter. Filter records within one or several day or week ranges.
-
Stream and _stream_id filters. Filter by specific log streams (Stream filter, _stream_id filter).
-
Word, phrase, and prefix filters: Match logs containing certain words, exact phrases, or prefix strings.
These filters can be combined to build precise log queries. For specific syntax and more detailed examples, go to https://docs.victoriametrics.com/victorialogs/logsql/index.html
Export logs
Exporting logs helps you to, for example, save log entries beyond the log retention period. You can export logs as .json files.
To export logs:
-
Send the query with the needed filters
-
Select the JSON tab.
-
Click
to download the logs. Change the name, if needed, and click Download . The files are in your default download location on your computer.