Managing server logs
Server logs help you monitor system activity, user actions, and rule-triggered events in XProtect. The following types of server logs are available:
Log type | What is logged? |
|---|---|
System logs | System activity, events, and errors |
Audit logs | User activity |
Rule-triggered logs | Rule-generated log entries. See Actions and stop actions for more information. |
You can view server logs in XProtect Management Client under Server Logs.
For information about logs used for troubleshooting, see Debug logs.
Search and filter logs
You can search and filter logs to find specific events or activities. The available filters include:
General filters for field values, words, phrases, and stream information
Searches across multiple fields
Time-based filters
Day and week range filters
Stream filters
Word, phrase, and prefix filters
You can combine filters to create more precise queries.
For detailed filter syntax and examples, see the VictoriaLogs documentation: LogsQL documentation
Export logs
Export logs if you need to retain log entries beyond the configured retention period or share them for analysis and auditing. Logs are exported as JSON files.
To export logs:
Run a query with the required filters.
Select the JSON tab.
Click the download button

The exported file is saved to your default download location.
Warning
For CAPSS-compliant systems, Milestone recommends storing exported logs on a secure write-once medium or applying digital signatures using Windows tools or third-party solutions.