Skip to main content

OpenTelemetry Audit Logs

Full example of SysLog exporter configuration

Last Updated: 3 minute read

The following configuration example shows how the OpenTelemetry Collector can be configured to export audit logs from XProtect services to a SysLog-compatible backend such as Graylog. Logs are ingested using the OTLP protocol over HTTP [8]. Authentication is handled through bearer tokens validated against an Identity Provider (IDP) [11], and the logs are enriched with identity metadata.

The configuration includes transformation logic in the log processor to structure log attributes from XProtect ser-vices into SysLog fields, ensuring compatibility with parsing and visualization tools in the backend. Export is then performed using the RFC5424 Syslog protocol over TLS [16].

Reliability is maintained through persistent file-based storage [12] and retry mechanisms [17], ensuring that logs are not lost during transmission failures.

extensions:

oidc/server: # OIDC extension with the unique name 'server' issuer_url: https://localhost/IDP # URL to IDP server

audience: serverlogs # Specific audience to verify on each incoming token issuer_ca_path: [PATH TO CERTIFICATE] # CA public certificate of IDP server attribute: authorization # Name of the header with the bearer token (Case sensitive!)

file_storage/server: # File storage extension with the unique name 'server' fsync: true # Ensure data integrity on each write

receivers:

otlp/server:

protocols:

http: # Use HTTP Protobuf

endpoint: "0.0.0.0:4318" # Listen on port 4318 and accept any address auth:

authenticator: oidc/server # OIDC extension configuration matching the unique name 'server' tls:

cert_file: [PATH TO SERVER CERTIFICATE] # Public server certificate key_file: [PATH TO SERVER CERTIFICATE KEY] # Private server key

processors:

resource/authtoken: # resource processor with the unique name 'authtoken' attributes:

  • key: oidc.sub # Include the subject of the token in the log message action: upsert

from_context: auth.subject transform/logs:

log_statements:

  • context: log statements:

    • set(attributes["priority"], 109)

# The following lines organize log attributes into structured data fields.

# Each field is given a unique SD-ID (e.g., XPCO_LEI) for consistent parsing in Graylog.

  • set(attributes["structured_data"]["XPCO_LoggingAuthSub"]["LoggingAuthSub"], resource.at-tributes["oidc.sub"]) # This line requires authentication to have been setup on the reciever.

  • set(attributes["structured_data"]["XPCO_LogEntryId"]["LogEntryId"], attrib-utes["LogEntryId"])

  • set(attributes["structured_data"]["XPCO_ResourceId"]["ResourceId"], attributes["Re-sourceId"])

  • set(attributes["structured_data"]["XPCO_ResourceName"]["ResourceName"], attributes["Re-sourceName"])

  • set(attributes["structured_data"]["XPCO_ResourceType"]["ResourceType"], attributes["Re-sourceType"])

  • set(attributes["structured_data"]["XPCO_Description"]["Description"], attributes["Descrip-

tion"])

  • set(attributes["structured_data"]["XPCO_SourceType"]["SourceType"], attributes["Source-

Type"])

  • set(attributes["structured_data"]["XPCO_LocationIPAddress"]["LocationIPAddress"], attrib-

utes["LocationIPAddress"])

  • set(attributes["structured_data"]["XPCO_UserCredentials"]["UserCredentials"], attrib-utes["UserCredentials"])

  • set(attributes["structured_data"]["XPCO_AuditType"]["AuditType"], attributes["AuditType"])

  • - set(attributes["structured_data"]["XPCO_AccessGranted"]["AccessGranted"], attributes["Ac-cessGranted"])

    # The next line sets the main "message" field to the log's Description for better visibility in Graylog.

    - set(attributes["message"], attributes["Description"])

  • exporters: syslog/graylog: # This exporter sends logs to Graylog using the syslog protocol. endpoint: "localhost" # IP address or hostname of the server. port: 5140 # Syslog port used by Graylog (commonly 514 or 1514). protocol: rfc5424 # Use RFC5424, the modern syslog standard. tls: ca_file: [PATH TO CERTIFICATE] # CA public certificate of the log backend sending_queue: # Queue logs in case logs cannot be exported to the backend enabled: true # It is disabled by default storage: file_storage/server block_on_overflow : true # Blocking is used to ensure the system stops working if logs cannot be created. retry_on_failure: # Additional retry options when logs cannot be exported to the backend max_elapsed_time: 0 # Disable max elapsed time to allow retries indefinitely  

  • service: extensions: [oidc/server, file_storage/server] # Load the extension configuration pipelines: logs/server: # LOGS pipeline with the unique name 'server' receivers: [otlp/server] # Use the OTLP receiver with the unique name 'server' processors: [resource/authtoken, transform/logs] # Use the resource and transform processors with unique names exporters: [syslog/graylog] # Use the otlphttp exporter with the unique name 'server'