Log forwarding allows you to stream logs in real time to an external endpoint for integration with your monitoring, analysis, and SIEM tools.
For log forwarding, Airlock as a Service currently supports syslog over mTLS and HTTP/JSON. Syslog messages are sent in RFC 3164 format over a TCP connection secured with mutual TLS. HTTP/JSON logs are sent as JSON arrays via HTTP POST.
Forwarded log sources
The following log sources are forwarded:
Airlock IAM: Structured logs generated by IAM application modules
Airlock Microgateway Engine: Access logs
Enabling log forwarding
On the Configuration tab, configure the following fields in the Log forwarding section:
Field |
Required |
Description |
|---|---|---|
Type |
Yes |
Select the endpoint type: Syslog (mTLS) or HTTP/JSON (JSON arrays via HTTP POST). |
Endpoint URL |
Yes |
Enter the URL of the log forwarding endpoint. For syslog endpoints, use the format |
Client certificate |
Yes |
Enter the X.509 client certificate in PEM format used for mTLS authentication. |
Private key |
Yes |
Enter the private key corresponding to the client certificate in PEM format. |
Server certificate |
No |
Enter the CA certificate in PEM format used to verify the server’s TLS certificate. If omitted, publicly trusted certificate authorities are used. |
Basic authentication |
No |
Available only for HTTP/JSON endpoints. Enables HTTP Basic authentication using a username and password in addition to the client certificate. |
Syslog message format
Each log entry is forwarded as a syslog message in RFC 3164 format. The fields are populated as follows:
Field |
Content |
Example |
|---|---|---|
|
Tenant ID |
|
|
Module and component in the format
|
|
|
Log payload in JSON format |
See the example below. |
{
"time": "2026-03-30T06:57:41.606+0000",
"log_id": "IAM-USERTRAIL",
"target_id": "fxvg3pw20ava",
"provided_id": "fxvg3pw20ava",
"message": "Successfully changed password upon mandatory change",
"host": "iam-loginapp-v1-7tqpq",
"program": "loginapp",
"priority": "info",
"instance": "auth",
"sess_id": "438282395745474485",
"req_id": "167c4685-ac0b-93af-86ac-9a0cc5ea526a",
"corr_id": "00-00eff822bf1e43d70adfb7730f81b238-2c02453d1852af99-01",
"configuration_context": "[DEFAULT]",
"environment": "[COMMON]"
}HTTP/JSON message format
Log entries are collected and buffered briefly before being sent in batches. Each batch is sent to the configured endpoint in a separate HTTP request with the following properties:
Request property |
Value |
|---|---|
Method |
|
Target |
The path and query string from the configured endpoint URL, or |
Content-Type |
|
Content-Encoding |
|
Authorization |
|
Body |
A JSON array containing the log events |
Each element in the array represents a single log event:
Field |
Content |
Example |
|---|---|---|
|
Time at which the log entry was collected, expressed in UTC using ISO 8601 format |
|
|
JSON-encoded string containing the log payload |
See the decoded JSON example below. |
{
"tenant_id": "xyz",
"component": "airlock-iam",
"module": "loginapp",
"severity": "info",
"record": {
"time": "2026-03-30T06:57:41.606+0000",
"log_id": "IAM-USERTRAIL",
"target_id": "fxvg3pw20ava",
"provided_id": "fxvg3pw20ava",
"message": "Successfully changed password upon mandatory change",
"host": "iam-loginapp-v1-xyz",
"program": "loginapp",
"priority": "info",
"instance": "auth",
"sess_id": "438282395745474485",
"req_id": "167c4685-ac0b-93af-86ac-9a0cc5ea526a",
"corr_id": "00-00eff822bf1e43d70adfb7730f81b238-2c02453d1852af99-01",
"configuration_context": "[DEFAULT]",
"environment": "[COMMON]"
}
}Certificate rotation
To rotate the client certificate, replace the configured certificate and its corresponding private key, then save the configuration. The new certificate takes effect immediately, without any downtime.
Disabling log forwarding
To disable log forwarding, click Reset in the Log forwarding section, then save the configuration.
Notice
Resetting the log forwarding configuration clears all configured values. The cleared values cannot be recovered.