Skip to main content

XProtect Management Client

Server Logs

Last Updated: 2 minute read
Version2026r1
LanguageEnglish

Note

This article describes the Server Logs functionality introduced in 2026 R1, which uses OpenTelemetry and VictoriaLogs. If your system uses the legacy Log Server, refer to the documentation for your XProtect version instead.

Introduction

XProtect server components generate log entries for system activity, events, and errors. Components running on the management server send log entries to the OpenTelemetry Collector using the OpenTelemetry Protocol (OTLP). In distributed deployments, log entries from components on other machines are routed through the API Gateway before they reach the collector. 

The OpenTelemetry Collector forwards log data to a log processing service. By default, this is VictoriaLogs.   

You can view system logs, audit logs, and rule logs in XProtect Management Client. From the Server Logs page, you can search, filter, and analyze log entries to investigate system activity, user actions, events, and errors.

Some logging settings, including retention and collection behavior, are managed outside XProtect Management Client through the OpenTelemetry Collector and VictoriaLogs configuration files.

OpenTelemetry and the OTLP protocol

OpenTelemetry is an open standard for collecting and transferring telemetry data, including logs. XProtect uses the OpenTelemetry Protocol (OTLP) to send log data between components in the logging infrastructure.  

Using OTLP makes the logging infrastructure more flexible. In addition to the default setup with VictoriaLogs, you can connect the system to external logging or monitoring solutions that support OTLP.

For more information, see the OpenTelemetry documentation: https://opentelemetry.io/docs/specs/otel/logs/

The OpenTelemetry Collector service

System logs, audit logs, and rule logs require a running OpenTelemetry Collector service on the Management Server. 

The OpenTelemetry Collector receives log data from XProtect server components and forwards it to the configured log processing service. By default, this is VictoriaLogs.

VictoriaLogs

VictoriaLogs serves as the log database engine for XProtect logs, handling log storage, querying, and analysis. It replaces the SQL Server-based log database used in earlier versions of XProtect. 

You can access log data from the Server Logs page in XProtect Management Client.  

By default, system logs and rule logs are retained for 7 days, and audit logs are retained for 30 days. Older log entries are automatically deleted when the retention period expires. You can modify the retention settings in the VictoriaLogs configuration files stored on the Management Server. For more information, see Set log retention policy.