Knowledge Article
Enabling Connector Logging in Identity Security Cloud
Author
neil_mcglennon
SailPoint
Overview
This set of instructions details how to enable logging in Identity Security Cloud via REST API.
Process
The process for enabling logging is as follows:
- Identify VA Cluster - Identify the VA cluster to enable logging on.
- Get Logging Config - Get the logging configurations for the existing VA cluster.
- Update Logging Config - Update the VA cluster to enable logging levels.
- Observe Logging Changes - See the changes to the logging levels.
Identify VA Cluster
First, we need to select the Virtual Appliance cluster that we intend to enable logging on. This is done by calling the following REST API:
GET /v2025/managed-clusters
If successful, this API will provide a response which looks like this:
[
{
"id": "2c9180866166b5b0016167c32ef31a66",
"name": "Development Cluster",
"description": "Development Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": null
},
{
"id": "2c9180846a93ce60016ab29f039944de",
"name": "Cloud Cluster",
"description": "Cloud Cluster",
"clientType": "CCG",
"ccgVersion": "373_535_70.2.0",
"pinnedConfig": true,
"logConfiguration": {
"clientId": null,
"durationMinutes": 60,
"expiration": "2020-12-15T19:13:36.079Z",
"rootLevel": "INFO",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "DEBUG"
}
}
}
]
Note: Notice in the example above how one cluster has a log configuration and the other doesn’t. This is because we’ve already set logging on one of the clusters already. This is just to illustrate examples.
Identify the cluster by name or description which you want to enable logging on. Make sure to copy the id attribute of the VA cluster you are interested in as you will use it in the next step.
Get Logging Config
Next, we’ll want to get the VA cluster’s logging config. This is done by calling:
GET /v2025/managed-clusters/{id}/log-config
Where {id} is the VA cluster ID from the Identify VA Cluster step.
If there is no logging config, then you should receive a 204 No Content response. If there is a logging config, then API will provide a response which looks like this:
{
"clientId": null,
"durationMinutes": 60,
"expiration": "2020-12-15T19:13:36.079Z",
"rootLevel": "INFO",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "DEBUG"
}
}
Where:
- durationMinutes is the number of minutes to enable the logging.
- rootLevel is the default level for all logs. See Logging Levels for more details.
- logLevels is a map object with logging classes as keys, and logging levels as values.
- For keys, see the Logging Classes section for commonly used logging classes.
- For values, see the Logging Levels section for more details.
This can be used in the next section to modify the existing configurations.
Update Logging Config
Next, we’ll update the VA cluster configuration to update the logging settings. The logging REST API we’ll use is the following:
PUT /v2025/managed-clusters/{id}/log-config
Where {id} is the VA cluster ID from the Identify VA Cluster step.
This API also expects a JSON body of the updated logging configuration. It can be based on the previous step, Get Logging Config if there is already a configuration you are modifying, or you can craft a new logging configuration. Either way, the JSON body should look something like this:
{
"durationMinutes": 60,
"rootLevel": "INFO",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "DEBUG"
}
}
Note: Since this is a JSON body, this API expects a Content-Type: application/json header.
Where:
- durationMinutes is the number of minutes to enable the logging. You have to give this a value.
- rootLevel is the default level for all logs. See Logging Levels for more details.
- logLevels is a map object with logging classes as keys, and logging levels as values.
- For keys, see the Logging Classes section for commonly used logging classes.
- For values, see the Logging Levels section for more details.
Once this is sent, we should see a response.
If successful, this API will provide a response which looks like this:
{
"clientId": null,
"durationMinutes": 60,
"expiration": "2020-12-15T19:13:36.079Z",
"rootLevel": "INFO",
"logLevels": {
"sailpoint.connector.ADLDAPConnector": "DEBUG"
}
}
At this point, there is nothing more to configure. The expiration setting should provide guidance around how long this logging change will be enabled for.
Observe Logging Changes
After you have made the logging changes to the VA cluster, it should take about 5 minutes for the updates to be picked up. Once picked up the VA logs should show the desired output in the ccg.log.
Note: These VA logging changes are not instant! They may take around 5 minutes to propagate.
Reference
Logging Levels
Available values for logging levels are as follows:
Logging Level Description
ERROR: Designates error events that might still allow the connector to continue.
WARN: Designates potentially harmful situations.
INFO: Designates information messages that highlight process at a coarse-grain level.
DEBUG: Very verbose. Fine grain logging levels used for development and debugging.
TRACE: Most verbose. Finer grain logging levels than debugging.
ERROR | Designates error events that might still allow the connector to continue. | |
WARN | Designates potentially harmful situations. | |
INFO | Designates information messages that highlight process at a coarse-grain level. | |
DEBUG | Very verbose. Fine grain logging levels used for development and debugging. | |
TRACE | Most verbose. Finer grain logging levels than debugging. |
Note: The root level should never be set to trace.
Logging Classes
Connector
Logging Class
| Connector | Logging Class | |
|---|---|---|
Active Directory | sailpoint.connector.ADLDAPConnector sailpoint.connector.activedirectory | |
AIX | openconnector.connector.unix.AIXConnector | |
Atlassian | openconnector.connector.atlassian | |
Azure Active Directory | sailpoint.connector.AzureADConnector sailpoint.connector.azuread sailpoint.connector.microsoft.rest.service | |
Box | openconnector.connector.BoxNetConnector | |
Cerner | openconnector.connector.CernerConnector | |
Coupa | openconnector.connector.coupa.CoupaConnector | |
Dropbox | openconnector.connector.DropBoxConnector | |
Epic | openconnector.connector.EPICConnector | |
GE Centricity | openconnector.connector.GECentricity | |
Google Apps / G Suite | openconnector.connector.GoogleAppsDirect | |
IBM i | openconnector.connector.IBMiConnector | |
Lotus Domino |
| |
JDBC | sailpoint.connector.JDBCConnector | |
Sun One LDAP | sailpoint.connector.LDAPConnector | |
Linux | openconnector.connector.unix.LinuxConnector | |
LDAP Connector | sailpoint.connector.LDAPConnector | |
Microsoft Office365 | sailpoint.connector.Office365Connector | |
Microsoft SQL Server | sailpoint.connector.mssql.serviceimpl.MSSQLServerConnectorV2 | |
Okta | openconnector.connector.okta | |
Open LDAP | sailpoint.connector.LDAPConnector | |
Oracle Database | sailpoint.connector.OracleDBConnector | |
Oracle E-Business | sailpoint.connector.OracleEBSConnector | |
Oracle ERP | openconnector.connector.oracleerp | |
Oracle EPM Cloud | openconnector.connector.oracleepmcloud | |
Oracle Fusion HCM | openconnector.connector.oraclefusionhcm | |
Oracle HRMS | sailpoint.connector.OracleAppsHRMSConnector | |
PeopleSoft | openconnector.connector.PeopleSoftConnector | |
PeopleSoftHRMS | sailpoint.connector.PeopleSoftHRMSConnector | |
RemedyForce | sailpoint.connector.ForceConnector | |
RSA Authentication Manager | openconnector.connector.RSAConnector openconnector.connector.rsa | |
Salesforce | sailpoint.connector.ForceConnector sailpoint.connector.salesforce | |
SAP - Direct | sailpoint.connector.SAPConnector | |
SAP HR/HCM | sailpoint.connector.SAPHRInternalConnector | |
SAP Concur | openconnector.connector.sapconcur | |
SAP GRC | sailpoint.connector.SAPGRCConnector sailpoint.connector.sapgrc | |
SAP Portal | sailpoint.connector.SAPPortalSOAPConnector | |
SCIM 1.1 | openconnector.connector.SCIMConnector | |
SCIM 2.0 | openconnector.connector.scim2.SCIM2Connector | |
ServiceNow |
| |
ServiceNow Service Desk Integration | openconnector.connector.servicedesk | |
Siebel | openconnector.connector.SiebelConnector | |
Slack | openconnector.connector.slack | |
Snowflake | openconnector.connector.snowflake.SnowflakeConnector | |
Solaris | openconnector.connector.unix.SolarisConnector | |
SuccessFactors | sailpoint.connector.SuccessFactorsConnector | |
Sybase | sailpoint.connector.SybaseDirectConnector | |
Webex | openconnector.connector.Webex | |
Workday | openconnector.connector.WorkDay | |
Workday Accounts | openconnector.connector.workdayaccounts | |
Web Services | sailpoint.connector.webservices connector.sdk.webservices org.apache.http.wire (For details over wire Only) | |
XML | openconnector.connector.XMLConnector | |
Yammer | openconnector.connector.YammerConnector | |
Zoom | openconnector.connector.zoom.ZoomConnector |