Server Logs node
VictoriaLogs (tab)
The VictoriaLogs tab provides access to system logs, audit logs, and rule logs collected from across the XProtect system.
The VictoriaLogs tab displays a combined view of these log types. You can use the VictoriaLogs interface to search, filter, and investigate log data across the system.
To open VictoriaLogs, select one of these options:
View server logs in VictoriaLogs opens a new log view with default settings
Continue last session restores the most recently used log view, including any filters or queries applied
For information about supported functionality, querying capabilities, and advanced usage, refer to the VictoriaLogs documentation: https://docs.victoriametrics.com/victorialogs/
If you have migrated to OpenTelemetry and VictoriaLogs, you may see the message: Log server not registered. Add the log server to your registered services. This message is expected and indicates that the system now reports to VictoriaLogs.
If you still see entries in Audit logs, System logs, or Rule‑triggered logs tabs, this means that either your existing log data has not yet expired or one or more system components still report to the log server.
Once all components are migrated and existing logs have expired according to retention settings, these entries will no longer appear.
Other tabs
After migrating to OpenTelemetry and VictoriaLogs, you may see the following message: Log server not registered. Add the log server to your registered services.
This message is expected. It indicates that log data is now being sent to VictoriaLogs instead of the legacy Log Server.
You may continue to see entries on the Audit logs, System logs, and Rule-triggered logs tabs until existing log data expires or all components have been migrated.
System logs (tab)
Each row in a log represents a log entry. A log entry contains a number of information fields:
Name | Description |
|---|---|
Log level | Info, warning, or error. |
Local time | Timestamped in the local time of your system's server. |
Message text | The identification number for the logged incident. |
Category | The type of logged incident. |
Source type | The type of equipment on which the logged incident occurred, for example, server or device. |
Source name | The name of the equipment on which the logged incident occurred. |
Event type | The type of event represented by the logged incident. |
Audit logs (tab)
Each row in a log represents a log entry. A log entry contains a number of information fields:
Name | Description |
|---|---|
Local time | Timestamped in the local time of your system's server. |
Message text | Shows a description of the logged incident. |
Permission | The information about whether the remote user action was allowed (granted) or not. |
Category | The type of logged incident. |
Source type | The type of equipment on which the logged incident occurred, for example, server or device. |
Source name | The name of the equipment on which the logged incident occurred. |
User | The user name of the remote user causing the logged incident. |
User location | The IP address or host name of the computer from which the remote user caused the logged incident. |
Rule-triggered logs (tab)
Each row in a log represents a log entry. A log entry contains a number of information fields:
Name | Description |
|---|---|
Local time | Timestamped in the local time of your system's server. |
Message text | Shows a description of the logged incident. |
Category | The type of logged incident. |
Source type | The type of equipment on which the logged incident occurred, for example, server or device. |
Source name | The name of the equipment on which the logged incident occurred. |
Event type | The type of event represented by the logged incident. |
Rule name | The name of the rule triggering the log entry. |
Service name | The name of the service on which the logged incident occurred. |