[en] Server Logs
Note
[en] This article describes the Server Logs functionality introduced in 2026 R1, which uses OpenTelemetry and VictoriaLogs. If your system uses the legacy Log Server, refer to the documentation for your XProtect version instead.
[en] Introduction
Les composants du serveur VMS XProtect génèrent des entrées de journal pour l'activité du système, les événements et les erreurs. Ces entrées de journal sont collectées et envoyées à l’aide d’OpenTelemetry via le protocole OpenTelemetry Protocol (OTLP).
[en] The OpenTelemetry Collector forwards log data to a log processing service. By default, this is VictoriaLogs.
[en] You can view system logs, audit logs, and rule logs in XProtect Management Client. From the Server Logs page, you can search, filter, and analyze log entries to investigate system activity, user actions, events, and errors.
[en] Some logging settings, including retention and collection behavior, are managed outside XProtect Management Client through the OpenTelemetry Collector and VictoriaLogs configuration files.
[en] OpenTelemetry and the OTLP protocol
[en] OpenTelemetry is an open standard for collecting and transferring telemetry data, including logs. XProtect uses the OpenTelemetry Protocol (OTLP) to send log data between components in the logging infrastructure.
[en] Using OTLP makes the logging infrastructure more flexible. In addition to the default setup with VictoriaLogs, you can connect the system to external logging or monitoring solutions that support OTLP.
Pour un aperçu général de la façon dont OpenTelemetry gère les journaux en tant que signal de télémétrie, reportez-vous à la section Journalisation OpenTelemetry dans la documentation OpenTelemetry :https://opentelemetry.io/docs/specs/otel/logs/.
Le service OpenTelemetry Collector
Les journaux de serveur nécessitent l’exécution d’un service OpenTelemetry Collector. Les composants du serveur XProtect envoient les journaux au collecteur à l'aide du protocole OpenTelemetry Protocol (OTLP), et le collecteur transmet les journaux à VictoriaLogs ou à une solution de journalisation externe.
[en] The OpenTelemetry Collector receives log data from XProtect server components and forwards it to the configured log processing service. By default, this is VictoriaLogs.
[en] VictoriaLogs
[en] VictoriaLogs serves as the log database engine for XProtect logs, handling log storage, querying, and analysis. It replaces the SQL Server-based log database used in earlier versions of XProtect.
[en] You can access log data from the Server Logs page in XProtect Management Client.
[en] By default, system logs and rule logs are retained for 7 days, and audit logs are retained for 30 days. Older log entries are automatically deleted when the retention period expires. You can modify the retention settings in the VictoriaLogs configuration files stored on the Management Server. For more information, see Set log retention policy.