14.2 Configuring and Leveraging Syslog

Key Takeaways

  • IdentityIQ Syslog stores WARN, ERROR, and FATAL events, with stack traces, in the database; it is unrelated to the operating system's syslog service.

  • Syslog is enabled on Global Settings > IdentityIQ Configuration > Miscellaneous, where you set the lowest stored level (FATAL, ERROR, or WARN) and the days before deletion.

  • The incident code shown in a UI error banner is searched in Advanced Analytics > Syslog to retrieve the full stack trace.

  • Each Syslog event records the Server, which makes it especially useful in multi-host clusters.

  • The Perform Maintenance task's Prune syslog events option deletes events older than the configured age.

Last updated: September 2026

Configuring and Leveraging Syslog

Objective 6.2 is configure and leverage Syslog. In IdentityIQ, Syslog means a database record of errors, stored as syslog events, that administrators can search from the UI. It is not the Unix syslog daemon or a remote syslog server, which is a common source of confusion. The documentation describes a syslog event as "a capture of an error in the system, including the stack trace of the error."

Why Syslog Exists

Log files live on each server's disk, rotate away, and are often out of reach for administrators. Syslog puts the most important events, warnings, errors, and fatal errors, into the database, where anyone with the right access can search them. Each record includes the server that produced it, the user, and the stack trace. SailPoint notes that the Syslog search page is "used primarily to determine specific support information that SailPoint IdentityIQ support engineers can use for troubleshooting."

Configuration

Go to gear icon > Global Settings > IdentityIQ Configuration > Miscellaneous > Syslog Settings:

SettingMeaning
Enable syslogTurns capture on
Level at which syslog events will be storedThe lowest level stored: FATAL, ERROR, or WARN. Lower levels, such as INFO and DEBUG, are never stored in Syslog. They go only to Log4j appenders (section 14.1).
Days before syslog event deletionHow long events are kept before they become eligible for purging

The Perform Maintenance task's Prune syslog events option deletes events older than that age. Choosing WARN captures more detail but grows the table faster, so pick the level that fits your retention period and support needs.

From Incident Code to Stack Trace

When something fails in the UI, IdentityIQ shows a banner such as:

"The system has encountered a serious error while processing your request. Please report the following incident code to your system administrator: <incident code>"

The documented procedure:

  1. Note the incident code. Codes are specific to your environment.
  2. Go to Intelligence > Advanced Analytics and choose the Syslog search type.
  3. Enter the Incident Code and run the search.
  4. Open the event to see its stack trace. Attach it to a SailPoint Support case if you need to escalate.

Syslog Search Criteria

FieldUse
Incident CodeThe ID shown at the end of a UI error message
ServerThe host where the exception happened, which is vital in clustered environments
LevelWARN, ERROR, or FATAL
UsernameThe user, or a system process, performing the action
ClassnameThe Java class that raised the exception
MessageThe exception message
Line / Thread NameWhere and in which thread the error occurred
Start Date / End DateA time window

Like other Advanced Analytics searches, you can choose Fields to Display, save a Syslog search, or save it as a report and schedule it. A daily "errors on the task servers in the last 24 hours" report is a cheap early-warning system.

Using Syslog in a Debugging Routine

SituationSyslog helps by…Pair it with…
A user reports a UI errorFinding the exact stack trace by incident codeThe Debug pages (section 15.1) to inspect the objects involved
A task ended with errors overnightListing ERROR events by date, server, and classTask results and the Administrator Console (section 15.2)
An intermittent problem on one nodeFiltering by Serverlog4j DEBUG on that node only (section 14.1)
A custom rule throws exceptionsFiltering by Classname or MessageThe rule's own named logger

Worked Example: An Overnight Task Failure

The nightly Identity Refresh finished with errors, and the task result says only that some identities failed.

  1. In Advanced Analytics > Syslog, set the date range to last night and Level to ERROR.
  2. Sort or filter by Classname. Most errors point to a custom rule class and the same Message, a null pointer.
  3. The Server column shows that every error came from one task host, so the problem is data or code, not a single failing node. Open one event's stack trace to find the rule and line.
  4. Turn on the rule's DEBUG logger on that host (section 14.1), refresh one affected identity from the console, and read the log to see which attribute was null.
  5. Fix the rule, rerun the refresh, and save the Syslog search as a daily report so the next regression is caught the same morning.

Syslog, Log Files, and Audit Compared

SourceContainsBest for
Syslog (database)WARN, ERROR, and FATAL events with stack tracesFinding and sharing errors from the UI, by incident code
Log4j log filesEvery level you enable, per hostDetailed step-by-step diagnosis
Audit events (section 8.3)Business actions you chose to auditWho did what, for compliance

Common Misconceptions

  • "Enable syslog forwards events to our SIEM." No. It stores events in IdentityIQ's own database. Getting data to a SIEM uses other features, such as audit exports or log appenders.
  • "Syslog will show my debug statements." No. Only WARN, ERROR, and FATAL are stored.
  • "Syslog keeps events forever." Not if Perform Maintenance prunes them after the configured number of days.
Test Your Knowledge

A user sees an error banner containing an incident code. What is the documented way to find the underlying stack trace?

A

Search for the incident code in Intelligence > Advanced Analytics with the Syslog search type.

B

Run the logConfig command with the incident code.

C

Open the application server's operating-system syslog daemon.

D

Look up the code in the Audit Configuration page.

Test Your Knowledge

Where is the lowest severity level stored in IdentityIQ's Syslog configured, and what choices are available?

A

In log4j2.properties, with any level from TRACE to FATAL

B

On Global Settings > IdentityIQ Configuration > Miscellaneous, with FATAL, ERROR, or WARN

C

On the Audit Configuration page, with Success or Failure

D

In the Administrator Console, per host

Test Your Knowledge

Why is the Server field in Syslog search especially valuable?

A

It shows which database server stored the event.

B

It identifies the SMTP server used for alerts.

C

It lists the servers in the Access History database.

D

It identifies which IdentityIQ host raised the exception, which helps isolate problems in a clustered environment.

Test Your Knowledge

Syslog events older than the configured number of days are still in the database. Which task option removes them?

A

Refresh Role Indexes

B

Full Text Index Refresh

C

Perform Maintenance with Prune syslog events enabled

D

Account Aggregation with Detect deleted accounts

Sections you finish are checked off in the contents.