Skip to main content

XProtect Management Client

Server Logs node

Last Updated: 3 minute read
Version2026r1
LanguageEnglish

VictoriaLogs (tab)

The VictoriaLogs tab provides access to system logs, audit logs, and rule logs collected from across the XProtect system.

The VictoriaLogs tab displays a combined view of these log types. You can use the VictoriaLogs interface to search, filter, and investigate log data across the system.

To open VictoriaLogs, select one of these options:

  • View server logs in VictoriaLogs opens a new log view with default settings

  • Continue last session restores the most recently used log view, including any filters or queries applied

For information about supported functionality, querying capabilities, and advanced usage, refer to the VictoriaLogs documentation: https://docs.victoriametrics.com/victorialogs/

If you have migrated to OpenTelemetry and VictoriaLogs, you may see the message: Log server not registered. Add the log server to your registered services. This message is expected and indicates that the system now reports to VictoriaLogs.

If you still see entries in Audit logs, System logs, or Rule‑triggered logs tabs, this means that either your existing log data has not yet expired or one or more system components still report to the log server.

Once all components are migrated and existing logs have expired according to retention settings, these entries will no longer appear.

Other tabs

After migrating to OpenTelemetry and VictoriaLogs, you may see the following message: Log server not registered. Add the log server to your registered services. 

This message is expected. It indicates that log data is now being sent to VictoriaLogs instead of the legacy Log Server. 

You may continue to see entries on the Audit logs, System logs, and Rule-triggered logs tabs until existing log data expires or all components have been migrated.

System logs (tab)

Each row in a log represents a log entry. A log entry contains a number of information fields:

Name

Description

Log level

Info, warning, or error.

Local time

Timestamped in the local time of your system's server.

Message text

The identification number for the logged incident.

Category

The type of logged incident.

Source type

The type of equipment on which the logged incident occurred, for example, server or device.

Source name

The name of the equipment on which the logged incident occurred.

Event type

The type of event represented by the logged incident.

Audit logs (tab)

Each row in a log represents a log entry. A log entry contains a number of information fields:

Name

Description

Local time

Timestamped in the local time of your system's server.

Message text

Shows a description of the logged incident.

Permission

The information about whether the remote user action was allowed (granted) or not.

Category

The type of logged incident.

Source type

The type of equipment on which the logged incident occurred, for example, server or device.

Source name

The name of the equipment on which the logged incident occurred.

User

The user name of the remote user causing the logged incident.

User location

The IP address or host name of the computer from which the remote user caused the logged incident.

Rule-triggered logs (tab)

Each row in a log represents a log entry. A log entry contains a number of information fields:

Name

Description

Local time

Timestamped in the local time of your system's server.

Message text

Shows a description of the logged incident.

Category

The type of logged incident.

Source type

The type of equipment on which the logged incident occurred, for example, server or device.

Source name

The name of the equipment on which the logged incident occurred.

Event type

The type of event represented by the logged incident.

Rule name

The name of the rule triggering the log entry.

Service name

The name of the service on which the logged incident occurred.