[GH-ISSUE #2122] Feature Request: Tactical RMM Audit Log to File in /var/log #3263

Open
opened 2026-03-14 06:59:45 +03:00 by kerem · 3 comments
Owner

Originally created by @redanthrax on GitHub (Jan 21, 2025).
Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/2122

Originally assigned to: @wh1te909 on GitHub.

Is your feature request related to a problem? Please describe.
I need a way to scrape the audit log and store it externally.

Describe the solution you'd like
I would like the tacticalrmm audit log to log to a file in or a directory in /var/log and end with a .log extension.

Describe alternatives you've considered
Scheduling a script to pull the audit log data from the db and place the data in /var/log.

Additional context
The purpose is to scrape the data with promtail.

Originally created by @redanthrax on GitHub (Jan 21, 2025). Original GitHub issue: https://github.com/amidaware/tacticalrmm/issues/2122 Originally assigned to: @wh1te909 on GitHub. **Is your feature request related to a problem? Please describe.** I need a way to scrape the audit log and store it externally. **Describe the solution you'd like** I would like the tacticalrmm audit log to log to a file in or a directory in /var/log and end with a .log extension. **Describe alternatives you've considered** Scheduling a script to pull the audit log data from the db and place the data in /var/log. **Additional context** The purpose is to scrape the data with promtail.
Author
Owner

@wulfsystems commented on GitHub (Jul 23, 2025):

from my POV its an important featurerequest.
I for example want to check the tactical logs by splunk.

<!-- gh-comment-id:3105655642 --> @wulfsystems commented on GitHub (Jul 23, 2025): from my POV its an important featurerequest. I for example want to check the tactical logs by splunk.
Author
Owner

@eastedentech commented on GitHub (Jan 20, 2026):

Yeah, I would like to push those logs to something like Wazuh or similar.

Or just be able to add a syslog destination so TRMM can just send the logs direct to a syslog ingestion point.

<!-- gh-comment-id:3773705188 --> @eastedentech commented on GitHub (Jan 20, 2026): Yeah, I would like to push those logs to something like Wazuh or similar. Or just be able to add a syslog destination so TRMM can just send the logs direct to a syslog ingestion point.
Author
Owner

@bensen1 commented on GitHub (Jan 26, 2026):

Would be highly appreciated by us too! ; )

<!-- gh-comment-id:3800741345 --> @bensen1 commented on GitHub (Jan 26, 2026): Would be highly appreciated by us too! ; )
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/tacticalrmm#3263
No description provided.