Log Profiles (Audit & Notification Governance)
Table of Contents
Section titled βTable of Contentsβ- Overview & Audit Architecture
- Business & Operational Significance
- π― User Roles & Key Capabilities
- Visual Interface & Layout
- Policy Matrix Reference & Event Triggers
- The Four Official System Log Profiles
- Protection of System Profiles & Cloning Rules
- High-Volume Storage & Database Partitioning
- Troubleshooting & Verification
- Model Context Protocol (MCP) AI Integration
- Glossary
1. Overview & Audit Architecture
Section titled β1. Overview & Audit ArchitectureβIn Ring2All SBC, the Log Profiles module governs the recording, retention, and notification dispatching of administrative events across the session border controller. Operating completely orthogonal to Role Profiles (which dictate what an operator can do), Log Profiles dictate what the platform records and alerts on when that operator performs an action.
Administrative User Action (e.g. Delete Carrier Gateway) β βΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ User Context: Assigned Log Profile ββ (e.g., "Critical Actions Only" Profile) βββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββ β βΌββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ Log Profile Policy Evaluation ββ Target: "routing.carriers" | Event: DELETE βββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββ β βββββββββββββββ΄ββββββββββββββ β β βΌ βΌ[log_delete == true] [notify_delete == true] INSERT INTO audit_log Dispatch SMTP Alert Capture Before/After JSON Send PagerDuty / WebhookThis decoupled design enables organizations to enforce comprehensive audit logging for contractors or junior technicians while avoiding log volume saturation during routine high-frequency administrative tasks.
2. Business & Operational Significance
Section titled β2. Business & Operational Significanceβ- Forensic Post-Mortem Integrity: Supplies indisputable before-and-after change diffs when diagnosing sudden routing loops, trunk dropouts, or misconfigured IP firewall entries.
- Proactive Security Alerting: Automatically dispatches real-time email or webhook notifications the instant sensitive security parameters (such as TLS certificates or API keys) are deleted or updated.
- Telecom Compliance Readiness: Satisfies rigorous telecommunications compliance frameworks (SOC 2 Type II, ISO 27001, PCI-DSS Level 1, HIPAA) by maintaining non-repudiable evidentiary records.
- Storage Optimization: Allows administrators to restrict logging to destructive actions (
Critical Actions Only) on high-turnover systems, preventing unneeded storage bloat.
3. π― User Roles & Key Capabilities
Section titled β3. π― User Roles & Key Capabilitiesβ| Role | Primary Use Case | Key Capabilities |
|---|---|---|
| Chief Compliance Officer | Regulatory Audit Policy Design | Define enterprise log capture policies, mandate notification triggers for high-risk actions, and audit retention rules. |
| Security Auditor | Forensic Investigation & Tamper Review | Inspect audit logs, trace configuration modifications back to individual operator accounts, and verify log completeness. |
| SBC Systems Administrator | Audit Database Hygiene | Manage database partition maintenance, optimize indexing on audit_log, and tune logging frequency. |
| NOC Tier 3 Engineer | Operational Change Tracking | Monitor live administrative events, verify dispatcher update timestamps, and correlate change events with traffic shifts. |
| AI Platform Copilot / Administration Agent | Automated Audit Policy Auditing & Event Inspection | Query configured audit policies, verify retention rules, inspect syslog/file output triggers, and correlate audit logs via MCP. |
4. Visual Interface & Layout
Section titled β4. Visual Interface & LayoutβThe Log Profiles interface provides a summary table showing all audit profiles, their module event coverage indicators, system/custom flags, and a form modal for matrix tuning.
4.1 Log Profiles List View
Section titled β4.1 Log Profiles List ViewβDisplays existing audit profiles, inline module descriptions, compact 4-value indicators (Logs: C / E / D and Notif: C / E / D), and action buttons.

4.2 Log Profile Configuration Form
Section titled β4.2 Log Profile Configuration FormβForm modal presenting independent checkboxes for Log Capture (Create, Edit, Delete) and Real-time Notifications (Create, Edit, Delete) across all SBC modules.

5. Policy Matrix Reference & Event Triggers
Section titled β5. Policy Matrix Reference & Event TriggersβFor each module group, the profile governs six independent boolean event flags:
| Event Column | Operational Trigger | Database & Notification Impact |
|---|---|---|
Log Create (C) |
Submitting a new entity (e.g., new SIP Domain, new DID, new TLS Profile). | Records a new row in audit_log with the complete initial entity JSON state. |
Log Edit (E) |
Modifying an existing record (e.g., changing carrier weight, updating engine concurrency). | Records an update row in audit_log with before-and-after property diffs. |
Log Delete (D) |
Deleting an existing entity from the database or flushing memory. | Records a deletion row in audit_log with the last known snapshot of the destroyed entity. |
Notify Create (C) |
Successful creation of an entity. | Dispatches an immediate email alert via the configured SMTP gateway. |
Notify Edit (E) |
Successful modification of an entity. | Dispatches an alert containing the exact fields that were changed. |
Notify Delete (D) |
Deletion of an entity. | Dispatches a high-priority alarm notification with destroyed entity details. |
6. The Four Official System Log Profiles
Section titled β6. The Four Official System Log ProfilesβRing2All SBC provides four built-in audit templates:
| Profile Name | Event Coverage | Retention | Primary Use Case |
|---|---|---|---|
| Full Audit Trail | 100% Events (Create, Edit, Delete) | 365 Days | Rigorous enterprise environments requiring complete evidentiary records for all actions. |
| Critical Actions Only | Delete Events Only across all modules | 180 Days | Lean, storage-conscious deployments focusing strictly on destructive operations. |
| Security & Routing | Firewall, ACL, Carrier Trunks, Dispatchers | 180 Days | Telecom NOCs monitoring carrier interconnects and perimeter security without user UI noise. |
| Minimal / Disabled | Minimal system-level warnings | 30 Days | Staging, lab testing, or local sandbox SBC instances with constrained disk storage. |
7. Protection of System Profiles & Cloning Rules
Section titled β7. Protection of System Profiles & Cloning RulesβLike Role Profiles, system log templates (is_system = true) are protected:
- Delete Prohibition: Built-in profiles cannot be deleted from the database or UI.
- Duplication (
Copy): Clicking Copy clones the six-flag matrix to a new customizable profile, enabling granular tailoring without altering factory baselines.
8. High-Volume Storage & Database Partitioning
Section titled β8. High-Volume Storage & Database PartitioningβAudit records are partitioned on PostgreSQL 17 to maintain sub-millisecond query performance:
- Monthly Partitioning:
audit_logis physically partitioned bycreated_attimestamp ranges. - Automated Archiving: Completed monthly partitions older than 90 days are automatically archived to compressed cold storage or detached without impacting live platform performance.
9. Troubleshooting & Verification
Section titled β9. Troubleshooting & VerificationβInspecting Log Profiles in Database
Section titled βInspecting Log Profiles in DatabaseβVerify active log profiles and their system status:
sudo -u postgres psql -d sbc_admin -c "SELECT id, name, is_system, is_default, created_atFROM log_profilesORDER BY id;"Validating Recent Audit Log Captures
Section titled βValidating Recent Audit Log CapturesβConfirm that user actions are generating audit records according to their assigned profile:
sudo -u postgres psql -d sbc_admin -c "SELECT created_at, user_id, action, module, detailsFROM audit_logORDER BY created_at DESCLIMIT 5;"10. Model Context Protocol (MCP) AI Integration
Section titled β10. Model Context Protocol (MCP) AI IntegrationβRing2All SBC exposes dedicated Model Context Protocol (MCP) tools enabling AI agents, autonomous NOC bots, and administrative copilot assistants to query, audit, and inspect event logging policies.
Available MCP Tools
Section titled βAvailable MCP Toolsβ| Tool Name | Operation | Risk Level | Description |
|---|---|---|---|
list_sbc_log_profiles |
Read | Low (read) |
List all audit logging and event tracking profiles, retention periods, and target outputs (syslog/file). |
get_sbc_log_profile |
Read | Low (read) |
Retrieve detailed event logging levels, retention days, and module subscriptions for a specific log profile by UUID, slug, or name. |
Tool Schemas & Parameter Definitions
Section titled βTool Schemas & Parameter Definitionsβlist_sbc_log_profiles
Section titled βlist_sbc_log_profilesβ{ "name": "list_sbc_log_profiles", "description": "List audit logging and event tracking profiles, retention periods, and target outputs (syslog/file).", "inputSchema": { "type": "object", "properties": {} }}get_sbc_log_profile
Section titled βget_sbc_log_profileβ{ "name": "get_sbc_log_profile", "description": "Get detailed audit event logging levels and module subscriptions for a specific log profile by UUID, slug, or name.", "inputSchema": { "type": "object", "properties": { "identifier": { "type": "string", "description": "Log profile UUID, slug, or name" } }, "required": ["identifier"] }}Realistic Payload Examples
Section titled βRealistic Payload ExamplesβQuery Request (get_sbc_log_profile)
Section titled βQuery Request (get_sbc_log_profile)β{ "identifier": "full-audit-trail"}Successful Response (get_sbc_log_profile)
Section titled βSuccessful Response (get_sbc_log_profile)β{ "success": true, "data": { "logProfile": { "uuid": "b8f41029-47aa-4831-a068-3e5fa809d841", "name": "Full Audit Trail", "slug": "full-audit-trail", "description": "Rigorous enterprise environments requiring complete evidentiary records for all actions.", "log_level": "DEBUG", "log_modules": ["routing", "security", "technology", "admin"], "output_syslog": true, "output_file": true, "log_file_path": "/var/log/softswitch-sbc/audit.log", "retention_days": 365, "is_active": true, "is_default": true, "is_system": true, "users_count": 14, "created_at": "2026-01-15T08:00:00Z", "updated_at": "2026-08-10T12:00:00Z" } }}Natural Language Prompt Scenarios
Section titled βNatural Language Prompt ScenariosβEnglish (Compliance Retention Audit)
Section titled βEnglish (Compliance Retention Audit)ββCheck the active log profiles on Ring2All SBC and verify which profiles have retention periods shorter than 180 days or do not output to syslog.β
Spanish (InspecciΓ³n de Registro de AuditorΓa)
Section titled βSpanish (InspecciΓ³n de Registro de AuditorΓa)ββMuestra la configuraciΓ³n detallada del perfil de log βFull Audit Trailβ para confirmar si los eventos de eliminaciΓ³n de troncales y carriers estΓ‘n siendo enviados a syslog.β
Enterprise AI Safety Guardrails
Section titled βEnterprise AI Safety Guardrailsβ- Read-Only Telemetry Protection: AI agents can inspect logging policies and retention thresholds to audit compliance without modifying active syslog pipelines or altering audit retention periods.
- Audit Trail Non-Bypassability: The system logging framework is built directly into core middleware, ensuring that LLM actions are themselves recorded under the callerβs audit log profile.
11. Glossary
Section titled β11. Glossaryβ- Audit Log: A security record providing documentary evidence of the sequence of activities that have affected a specific operation or procedure.
- Orthogonal Access Architecture: A design pattern where user identity, functional permissions, audit logging, and AI capabilities are managed independently.
- Diff (Difference): A representation of the exact data modifications made between the previous state and the new state of an entity.
- Partitioning: Dividing a large database table into smaller, more manageable sub-tables to preserve query speed and enable rapid archiving.

