The Eviden KMS server outputs logs to the console by default at INFO level.
For OTLP metrics & traces: see Metrics & Traces (OTLP). For the monitoring stack (Grafana, VictoriaMetrics, OTel Collector): see Monitoring stack setup. For audit logging (compliance, SIEM): see Audit logging. For every log call-site across all components: see Log call-site reference.
The log level can be adjusted by setting either:
- the
RUST_LOGenvironment variable, - the
rust_logsetting in the TOML configuration file in the[logging]section, - the
--rust-logcommand line argument.
Available levels: trace, debug, info, warn, error. The default is info.
Example:
RUST_LOG=info,cosmian=info,cosmian_kms_server=info,actix_web=info,mysql=infoThe first info sets the default log level for all crates. Individual crates can be overridden:
- To get detailed logs of user requests, set
cosmian_kms_servertodebug:
RUST_LOG=info,cosmian=info,cosmian_kms_server=debug,actix_web=info,mysql=info- To debug HTTP issues, set
actix_webtodebug:
RUST_LOG=info,cosmian=info,cosmian_kms_server=info,actix_web=debug,mysql=info
⚠️ WARNING: Setting the log level todebugortracemay leak sensitive information in the logs.
Logging to the console is enabled by default. It can be disabled via:
- the
quietparameter in the TOML configuration file in the[logging]section, - the
--quietcommand line argument, - the
KMS_LOG_QUIETenvironment variable set totrue.
On Linux, logs can be redirected to syslog instead of stdout by setting:
- the
log_to_syslogparameter in the TOML configuration file in the[logging]section, - the
--log-to-syslogcommand line argument, - the
KMS_LOG_TO_SYSLOGenvironment variable set totrue.
The server can write daily rolling log files. File logging is disabled unless
rolling_log_dir is explicitly configured (via --rolling-log-dir, the
KMS_ROLLING_LOG_DIR environment variable, or the TOML configuration).
Log files are named <name>.YYYY-MM-DD, where <name> defaults to kms.
When rolling_log_dir is set without specifying a path (e.g. via the
configuration wizard), the recommended platform-specific defaults are:
| Platform | Default directory |
|---|---|
| Linux | /var/log/ |
| Windows | C:\\Users\\<username>\\AppData\\Local\\Eviden KMS Server |
| macOS | ~/Library/Logs/ |
Warning (Windows): The server does not expand Windows environment variables such as
%LOCALAPPDATA%in configuration files. If you overriderolling_log_dirinkms.toml, you must use the fully-expanded path, for example:rolling_log_dir = "C:\\\\Users\\\\<username>\\\\AppData\\\\Local\\\\Eviden KMS Server"When
rolling_log_diris not set, the server resolves theLOCALAPPDATAenvironment variable at runtime and defaults toC:\\Users\\<username>\\AppData\\Local\\Eviden KMS Server. When running as a Windows service under LocalSystem, the variable may not be set; the server then falls back toC:\\ProgramData\\Eviden KMS Server.Note (macOS): The server defaults to
~/Library/Logs/which is the standard per-user log directory on macOS and is writable without root. If you run the server as a LaunchDaemon (root), you may override this with--rolling-log-dir /Library/Logs/.Graceful fallback: If the configured rolling log directory does not exist and cannot be created, or is not writable by the current process, the server disables file logging with a warning message on stderr and continues operating normally. This prevents the server from panicking due to inaccessible log paths.
The directory and file name can be overridden via:
- the
rolling_log_dir/rolling_log_nameentries in the TOML configuration file ([logging]section), - the
--rolling-log-dir/--rolling-log-namecommand line arguments, - the
KMS_ROLLING_LOG_DIR/KMS_ROLLING_LOG_NAMEenvironment variables.