--- title: "Log Profiles (Audit & Notification Governance)" description: "Documentation for Log Profiles" --- ## Table of Contents 1. [Overview & Audit Architecture](#1-overview--audit-architecture) 2. [Business & Operational Significance](#2-business--operational-significance) 3. [🎯 User Roles & Key Capabilities](#3--user-roles--key-capabilities) 4. [Visual Interface & Layout](#4-visual-interface--layout) 5. [Policy Matrix Reference & Event Triggers](#5-policy-matrix-reference--event-triggers) 6. [The Four Official System Log Profiles](#6-the-four-official-system-log-profiles) 7. [Protection of System Profiles & Cloning Rules](#7-protection-of-system-profiles--cloning-rules) 8. [High-Volume Storage & Database Partitioning](#8-high-volume-storage--database-partitioning) 9. [Troubleshooting & Verification](#9-troubleshooting--verification) 10. [Model Context Protocol (MCP) AI Integration](#10-model-context-protocol-mcp-ai-integration) 11. [Glossary](#11-glossary) --- ## 1. Overview & Audit Architecture In **Ring2All SBC**, the **Log Profiles** module governs the recording, retention, and notification dispatching of administrative events across the session border controller. Operating completely orthogonal to Role Profiles (which dictate *what an operator can do*), Log Profiles dictate *what the platform records and alerts on* when that operator performs an action. ``` Administrative User Action (e.g. Delete Carrier Gateway) β”‚ β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ User Context: Assigned Log Profile β”‚ β”‚ (e.g., "Critical Actions Only" Profile) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ Log Profile Policy Evaluation β”‚ β”‚ Target: "routing.carriers" | Event: DELETE β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β–Ό β–Ό [log_delete == true] [notify_delete == true] INSERT INTO audit_log Dispatch SMTP Alert Capture Before/After JSON Send PagerDuty / Webhook ``` This decoupled design enables organizations to enforce comprehensive audit logging for contractors or junior technicians while avoiding log volume saturation during routine high-frequency administrative tasks. --- ## 2. Business & Operational Significance * **Forensic Post-Mortem Integrity**: Supplies indisputable before-and-after change diffs when diagnosing sudden routing loops, trunk dropouts, or misconfigured IP firewall entries. * **Proactive Security Alerting**: Automatically dispatches real-time email or webhook notifications the instant sensitive security parameters (such as TLS certificates or API keys) are deleted or updated. * **Telecom Compliance Readiness**: Satisfies rigorous telecommunications compliance frameworks (SOC 2 Type II, ISO 27001, PCI-DSS Level 1, HIPAA) by maintaining non-repudiable evidentiary records. * **Storage Optimization**: Allows administrators to restrict logging to destructive actions (`Critical Actions Only`) on high-turnover systems, preventing unneeded storage bloat. --- ## 3. 🎯 User Roles & Key Capabilities | Role | Primary Use Case | Key Capabilities | | :--- | :--- | :--- | | **Chief Compliance Officer** | Regulatory Audit Policy Design | Define enterprise log capture policies, mandate notification triggers for high-risk actions, and audit retention rules. | | **Security Auditor** | Forensic Investigation & Tamper Review | Inspect audit logs, trace configuration modifications back to individual operator accounts, and verify log completeness. | | **SBC Systems Administrator** | Audit Database Hygiene | Manage database partition maintenance, optimize indexing on `audit_log`, and tune logging frequency. | | **NOC Tier 3 Engineer** | Operational Change Tracking | Monitor live administrative events, verify dispatcher update timestamps, and correlate change events with traffic shifts. | | **AI Platform Copilot / Administration Agent** | Automated Audit Policy Auditing & Event Inspection | Query configured audit policies, verify retention rules, inspect syslog/file output triggers, and correlate audit logs via MCP. | --- ## 4. Visual Interface & Layout The Log Profiles interface provides a summary table showing all audit profiles, their module event coverage indicators, system/custom flags, and a form modal for matrix tuning. ### 4.1 Log Profiles List View Displays existing audit profiles, inline module descriptions, compact 4-value indicators (`Logs: C / E / D` and `Notif: C / E / D`), and action buttons. ![Log Profiles List View](/screenshots/sbc/admin/log-profiles/log-profiles-list.png) ### 4.2 Log Profile Configuration Form Form modal presenting independent checkboxes for Log Capture (`Create`, `Edit`, `Delete`) and Real-time Notifications (`Create`, `Edit`, `Delete`) across all SBC modules. ![Log Profile Configuration Form](/screenshots/sbc/admin/log-profiles/log-profile-form.png) --- ## 5. Policy Matrix Reference & Event Triggers For each module group, the profile governs six independent boolean event flags: | Event Column | Operational Trigger | Database & Notification Impact | | :--- | :--- | :--- | | **Log Create (`C`)** | Submitting a new entity (e.g., new SIP Domain, new DID, new TLS Profile). | Records a new row in `audit_log` with the complete initial entity JSON state. | | **Log Edit (`E`)** | Modifying an existing record (e.g., changing carrier weight, updating engine concurrency). | Records an update row in `audit_log` with before-and-after property diffs. | | **Log Delete (`D`)** | Deleting an existing entity from the database or flushing memory. | Records a deletion row in `audit_log` with the last known snapshot of the destroyed entity. | | **Notify Create (`C`)** | Successful creation of an entity. | Dispatches an immediate email alert via the configured SMTP gateway. | | **Notify Edit (`E`)** | Successful modification of an entity. | Dispatches an alert containing the exact fields that were changed. | | **Notify Delete (`D`)** | Deletion of an entity. | Dispatches a high-priority alarm notification with destroyed entity details. | --- ## 6. The Four Official System Log Profiles Ring2All SBC provides four built-in audit templates: | Profile Name | Event Coverage | Retention | Primary Use Case | | :--- | :--- | :--- | :--- | | **Full Audit Trail** | 100% Events (Create, Edit, Delete) | 365 Days | Rigorous enterprise environments requiring complete evidentiary records for all actions. | | **Critical Actions Only** | Delete Events Only across all modules | 180 Days | Lean, storage-conscious deployments focusing strictly on destructive operations. | | **Security & Routing** | Firewall, ACL, Carrier Trunks, Dispatchers | 180 Days | Telecom NOCs monitoring carrier interconnects and perimeter security without user UI noise. | | **Minimal / Disabled** | Minimal system-level warnings | 30 Days | Staging, lab testing, or local sandbox SBC instances with constrained disk storage. | --- ## 7. Protection of System Profiles & Cloning Rules Like Role Profiles, system log templates (`is_system = true`) are protected: 1. **Delete Prohibition**: Built-in profiles cannot be deleted from the database or UI. 2. **Duplication (`Copy`)**: Clicking **Copy** clones the six-flag matrix to a new customizable profile, enabling granular tailoring without altering factory baselines. --- ## 8. High-Volume Storage & Database Partitioning Audit records are partitioned on PostgreSQL 17 to maintain sub-millisecond query performance: * **Monthly Partitioning**: `audit_log` is physically partitioned by `created_at` timestamp ranges. * **Automated Archiving**: Completed monthly partitions older than 90 days are automatically archived to compressed cold storage or detached without impacting live platform performance. --- ## 9. Troubleshooting & Verification ### Inspecting Log Profiles in Database Verify active log profiles and their system status: ```bash sudo -u postgres psql -d sbc_admin -c " SELECT id, name, is_system, is_default, created_at FROM log_profiles ORDER BY id; " ``` ### Validating Recent Audit Log Captures Confirm that user actions are generating audit records according to their assigned profile: ```bash sudo -u postgres psql -d sbc_admin -c " SELECT created_at, user_id, action, module, details FROM audit_log ORDER BY created_at DESC LIMIT 5; " ``` --- ## 10. Model Context Protocol (MCP) AI Integration Ring2All SBC exposes dedicated Model Context Protocol (MCP) tools enabling AI agents, autonomous NOC bots, and administrative copilot assistants to query, audit, and inspect event logging policies. ### Available MCP Tools | Tool Name | Operation | Risk Level | Description | | :--- | :--- | :--- | :--- | | `list_sbc_log_profiles` | Read | Low (`read`) | List all audit logging and event tracking profiles, retention periods, and target outputs (syslog/file). | | `get_sbc_log_profile` | Read | Low (`read`) | Retrieve detailed event logging levels, retention days, and module subscriptions for a specific log profile by UUID, slug, or name. | ### Tool Schemas & Parameter Definitions #### `list_sbc_log_profiles` ```json { "name": "list_sbc_log_profiles", "description": "List audit logging and event tracking profiles, retention periods, and target outputs (syslog/file).", "inputSchema": { "type": "object", "properties": {} } } ``` #### `get_sbc_log_profile` ```json { "name": "get_sbc_log_profile", "description": "Get detailed audit event logging levels and module subscriptions for a specific log profile by UUID, slug, or name.", "inputSchema": { "type": "object", "properties": { "identifier": { "type": "string", "description": "Log profile UUID, slug, or name" } }, "required": ["identifier"] } } ``` ### Realistic Payload Examples #### Query Request (`get_sbc_log_profile`) ```json { "identifier": "full-audit-trail" } ``` #### Successful Response (`get_sbc_log_profile`) ```json { "success": true, "data": { "logProfile": { "uuid": "b8f41029-47aa-4831-a068-3e5fa809d841", "name": "Full Audit Trail", "slug": "full-audit-trail", "description": "Rigorous enterprise environments requiring complete evidentiary records for all actions.", "log_level": "DEBUG", "log_modules": ["routing", "security", "technology", "admin"], "output_syslog": true, "output_file": true, "log_file_path": "/var/log/softswitch-sbc/audit.log", "retention_days": 365, "is_active": true, "is_default": true, "is_system": true, "users_count": 14, "created_at": "2026-01-15T08:00:00Z", "updated_at": "2026-08-10T12:00:00Z" } } } ``` ### Natural Language Prompt Scenarios #### English (Compliance Retention Audit) > *"Check the active log profiles on Ring2All SBC and verify which profiles have retention periods shorter than 180 days or do not output to syslog."* #### Spanish (InspecciΓ³n de Registro de AuditorΓ­a) > *"Muestra la configuraciΓ³n detallada del perfil de log 'Full Audit Trail' para confirmar si los eventos de eliminaciΓ³n de troncales y carriers estΓ‘n siendo enviados a syslog."* ### Enterprise AI Safety Guardrails * **Read-Only Telemetry Protection**: AI agents can inspect logging policies and retention thresholds to audit compliance without modifying active syslog pipelines or altering audit retention periods. * **Audit Trail Non-Bypassability**: The system logging framework is built directly into core middleware, ensuring that LLM actions are themselves recorded under the caller's audit log profile. --- ## 11. Glossary * **Audit Log**: A security record providing documentary evidence of the sequence of activities that have affected a specific operation or procedure. * **Orthogonal Access Architecture**: A design pattern where user identity, functional permissions, audit logging, and AI capabilities are managed independently. * **Diff (Difference)**: A representation of the exact data modifications made between the previous state and the new state of an entity. * **Partitioning**: Dividing a large database table into smaller, more manageable sub-tables to preserve query speed and enable rapid archiving.