Full example of SysLog exporter configuration
The following configuration example shows how the OpenTelemetry Collector can be configured to export audit logs from XProtect services to a SysLog-compatible backend such as Graylog. Logs are ingested using the OTLP protocol over HTTP [8]. Authentication is handled through bearer tokens validated against an Identity Provider (IDP) [11], and the logs are enriched with identity metadata.
The configuration includes transformation logic in the log processor to structure log attributes from XProtect ser-vices into SysLog fields, ensuring compatibility with parsing and visualization tools in the backend. Export is then performed using the RFC5424 Syslog protocol over TLS [16].
Reliability is maintained through persistent file-based storage [12] and retry mechanisms [17], ensuring that logs are not lost during transmission failures.
extensions:
oidc/server: # OIDC extension with the unique name 'server' issuer_url: https://localhost/IDP # URL to IDP server
audience: serverlogs # Specific audience to verify on each incoming token issuer_ca_path: [PATH TO CERTIFICATE] # CA public certificate of IDP server attribute: authorization # Name of the header with the bearer token (Case sensitive!)
file_storage/server: # File storage extension with the unique name 'server' fsync: true # Ensure data integrity on each write
receivers:
otlp/server:
protocols:
http: # Use HTTP Protobuf
endpoint: "0.0.0.0:4318" # Listen on port 4318 and accept any address auth:
authenticator: oidc/server # OIDC extension configuration matching the unique name 'server' tls:
cert_file: [PATH TO SERVER CERTIFICATE] # Public server certificate key_file: [PATH TO SERVER CERTIFICATE KEY] # Private server key
processors:
resource/authtoken: # resource processor with the unique name 'authtoken' attributes:
key: oidc.sub # Include the subject of the token in the log message action: upsert
from_context: auth.subject transform/logs:
log_statements:
context: log statements:
set(attributes["priority"], 109)
# The following lines organize log attributes into structured data fields.
# Each field is given a unique SD-ID (e.g., XPCO_LEI) for consistent parsing in Graylog.
set(attributes["structured_data"]["XPCO_LoggingAuthSub"]["LoggingAuthSub"], resource.at-tributes["oidc.sub"]) # This line requires authentication to have been setup on the reciever.
set(attributes["structured_data"]["XPCO_LogEntryId"]["LogEntryId"], attrib-utes["LogEntryId"])
set(attributes["structured_data"]["XPCO_ResourceId"]["ResourceId"], attributes["Re-sourceId"])
set(attributes["structured_data"]["XPCO_ResourceName"]["ResourceName"], attributes["Re-sourceName"])
set(attributes["structured_data"]["XPCO_ResourceType"]["ResourceType"], attributes["Re-sourceType"])
set(attributes["structured_data"]["XPCO_Description"]["Description"], attributes["Descrip-
tion"])
set(attributes["structured_data"]["XPCO_SourceType"]["SourceType"], attributes["Source-
Type"])
set(attributes["structured_data"]["XPCO_LocationIPAddress"]["LocationIPAddress"], attrib-
utes["LocationIPAddress"])
set(attributes["structured_data"]["XPCO_UserCredentials"]["UserCredentials"], attrib-utes["UserCredentials"])
set(attributes["structured_data"]["XPCO_AuditType"]["AuditType"], attributes["AuditType"])
- set(attributes["structured_data"]["XPCO_AccessGranted"]["AccessGranted"], attributes["Ac-cessGranted"])
# The next line sets the main "message" field to the log's Description for better visibility in Graylog.
- set(attributes["message"], attributes["Description"])
exporters: syslog/graylog: # This exporter sends logs to Graylog using the syslog protocol. endpoint: "localhost" # IP address or hostname of the server. port: 5140 # Syslog port used by Graylog (commonly 514 or 1514). protocol: rfc5424 # Use RFC5424, the modern syslog standard. tls: ca_file: [PATH TO CERTIFICATE] # CA public certificate of the log backend sending_queue: # Queue logs in case logs cannot be exported to the backend enabled: true # It is disabled by default storage: file_storage/server block_on_overflow : true # Blocking is used to ensure the system stops working if logs cannot be created. retry_on_failure: # Additional retry options when logs cannot be exported to the backend max_elapsed_time: 0 # Disable max elapsed time to allow retries indefinitely
service: extensions: [oidc/server, file_storage/server] # Load the extension configuration pipelines: logs/server: # LOGS pipeline with the unique name 'server' receivers: [otlp/server] # Use the OTLP receiver with the unique name 'server' processors: [resource/authtoken, transform/logs] # Use the resource and transform processors with unique names exporters: [syslog/graylog] # Use the otlphttp exporter with the unique name 'server'