Airlock as a Service Knowledge Base

Log forwarding

Log forwarding allows you to stream logs in real time to an external endpoint for integration with your monitoring, analysis, and SIEM tools.

For log forwarding, Airlock as a Service currently supports syslog over mTLS and HTTP/JSON. Syslog messages are sent in RFC 3164 format over a TCP connection secured with mutual TLS. HTTP/JSON logs are sent as JSON arrays via HTTP POST.


Forwarded log sources

The following log sources are forwarded:

  • Airlock IAM: Structured logs generated by IAM application modules

  • Airlock Microgateway Engine: Access logs


Enabling log forwarding

On the Configuration tab, configure the following fields in the Log forwarding section:

Field

Required

Description

Type

Yes

Select the endpoint type: Syslog (mTLS) or HTTP/JSON (JSON arrays via HTTP POST).

Endpoint URL

Yes

Enter the URL of the log forwarding endpoint. For syslog endpoints, use the format tcp+tls://<host>:<port> (e.g., tcp+tls://syslog.example.com:6514).

Client certificate

Yes

Enter the X.509 client certificate in PEM format used for mTLS authentication.

Private key

Yes

Enter the private key corresponding to the client certificate in PEM format.

Server certificate

No

Enter the CA certificate in PEM format used to verify the server’s TLS certificate. If omitted, publicly trusted certificate authorities are used.

Basic authentication

No

Available only for HTTP/JSON endpoints. Enables HTTP Basic authentication using a username and password in addition to the client certificate.


Syslog message format

Each log entry is forwarded as a syslog message in RFC 3164 format. The fields are populated as follows:

Field

Content

Example

hostname

Tenant ID

7pvr7m

appname

Module and component in the format <module>/<component>

  • Modules: loginapp, adminapp

  • Components: airlock-iam, airlock-microgateway-engine

loginapp/airlock-iam

message

Log payload in JSON format

See the example below.


{
"time": "2026-03-30T06:57:41.606+0000",
"log_id": "IAM-USERTRAIL",
"target_id": "fxvg3pw20ava",
"provided_id": "fxvg3pw20ava",
"message": "Successfully changed password upon mandatory change",
"host": "iam-loginapp-v1-7tqpq",
"program": "loginapp",
"priority": "info",
"instance": "auth",
"sess_id": "438282395745474485",
"req_id": "167c4685-ac0b-93af-86ac-9a0cc5ea526a",
"corr_id": "00-00eff822bf1e43d70adfb7730f81b238-2c02453d1852af99-01",
"configuration_context": "[DEFAULT]",
"environment": "[COMMON]"
}


HTTP/JSON message format

Log entries are collected and buffered briefly before being sent in batches. Each batch is sent to the configured endpoint in a separate HTTP request with the following properties:

Request property

Value

Method

POST

Target

The path and query string from the configured endpoint URL, or / if the URL contains neither

Content-Type

application/json

Content-Encoding

gzip; the request body is always gzip-compressed

Authorization

Basic <credentials>; included only if a username and password are configured for Basic authentication

Body

A JSON array containing the log events


Each element in the array represents a single log event:

Field

Content

Example

@timestamp

Time at which the log entry was collected, expressed in UTC using ISO 8601 format

2026-03-30T06:57:41.606000Z

message

JSON-encoded string containing the log payload

See the decoded JSON example below.


{
"tenant_id": "xyz",
"component": "airlock-iam",
"module": "loginapp",
"severity": "info",
"record": {
"time": "2026-03-30T06:57:41.606+0000",
"log_id": "IAM-USERTRAIL",
"target_id": "fxvg3pw20ava",
"provided_id": "fxvg3pw20ava",
"message": "Successfully changed password upon mandatory change",
"host": "iam-loginapp-v1-xyz",
"program": "loginapp",
"priority": "info",
"instance": "auth",
"sess_id": "438282395745474485",
"req_id": "167c4685-ac0b-93af-86ac-9a0cc5ea526a",
"corr_id": "00-00eff822bf1e43d70adfb7730f81b238-2c02453d1852af99-01",
"configuration_context": "[DEFAULT]",
"environment": "[COMMON]"
}
}

Certificate rotation

To rotate the client certificate, replace the configured certificate and its corresponding private key, then save the configuration. The new certificate takes effect immediately, without any downtime.

Disabling log forwarding

To disable log forwarding, click Reset in the Log forwarding section, then save the configuration.

Notice

Resetting the log forwarding configuration clears all configured values. The cleared values cannot be recovered.