Logging to stdout only

In non-container setups, log output is usually written into dedicated log files in the local IAM instance directory. For containerized deployments, however, it is better to send the log information to standard output stdout instead of to local log files. This decouples the application from the infrastructure, and allows the container runtime to automatically capture, rotate, and route logs without risking local storage depletion.

This article explains how to log to stdout only.

Files to be specified:

Specifying instance.property

Three parameters in the instance.property file specify where IAM should write log output. The instance.property file is located in the instances/${instance.name}/ directory.

The following table lists the relevant parameters. It also shows how to configure them in order to write logs to stdout only.

Parameter

Description

Value

iam.log.structured-stdout.enabled

If enabled, writes structured log messages to standard output stdout.

true

This is the default value for setups based on Docker containers.

For details, see Logging parameters.

iam.log.structured-file.enabled

If enabled, writes structured log messages to log files in JSON Lines format.

false

This is the default value for setups based on Docker containers.

For details, see Logging parameters.

iam.log.main.enabled

If enabled, writes unstructured log messages to files in traditional format.

false

This is the default value.

Switching off appenders in all-modules.xml

In Log4J, appenders define where to log to. To prevent logs from being written to local files, disable the PARSABLE and IAM-AUDIT appenders.

 
Notice

Removing the PARSABLE appender stops log entries from being written to the *-parsable.log files. As a result, the Adminapp log viewer will no longer display log entries.

Perform the following steps:

  1. Open the all-modules.xml file in the instances/${instance.name}/log4j/ directory. The all-modules.xml file defines central logging settings valid for all IAM modules.
  2. Comment out the following code lines in the <Loggers> block:
    • <AppenderRef ref=“IAM-AUDIT”/>
    • <AppenderRef ref=“PARSABLE”/>
  3. See the following code block. The relevant lines are marked bold and italic:

  4.  
    Terminal box
    <?xml version="1.0" encoding="UTF-8"?> 
     
    <Configuration name="Custom Log4j 2 Configuration for All IAM Modules"> 
    	<Loggers> 
    		<Logger name="com.airlock.iam.log.audit"> 
    			<!-- <AppenderRef ref="IAM-AUDIT"/> --> 
    		</Logger> 
     
    		<Root level="${sys:iam.log.level}"> 
    			<!-- <AppenderRef ref="PARSABLE"/> --> 
    		</Root> 
    	</Loggers> 
    </Configuration>
  5. After modifying the instance.property and the all-modules.xml files, restart the IAM instance for the changes to take effect.
  6. IAM should now log to stdout only. To verify this, check that log files are no longer written to instances/${instance.name}/log4j/ but instead appear in the stdout container.

Further information and links

Internal links: