Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Usage Milestone: Time Field for Drupal 8+ Module time_field crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

JSONlog

901 sites Security covered Drupal 10–11
View on drupal.org

This module logs Drupal watchdog events in a JSON format, making them compatible with Logstash and Elasticsearch. It allows for flexible configuration through Drupal settings and server environment variables.

Logs watchdog events JSON-formatted

to log files.
Provides a Logstash/ElasticSearch-ready log source.

Drupal 7 and 11 compatible.

All Core versions have a stable release and work in a similar way using the same configurable settings as listed below.

Settings overridable by server environment vars

to secure simple and safe centralized configuration of multiple sites/hosts.
Just SetEnv drupal_[Drupal conf var] '[value]'.

  • jsonlog_severity_threshold: defaults to warning
  • jsonlog_truncate: defaults to 64 (Kb), logger uses file locking
  • jsonlog_site_id: defaults to server's hostname + database name + database prefix (if any))
  • jsonlog_canonical: name; for site identification across multiple instances
  • jsonlog_dir: defaults to PHP:ini error_log (unless that is 'syslog', then checks the usual suspects /var/log/...) + /drupal-jsonlog
  • jsonlog_file_time: none | Ymd (default) | YW | Ym
  • jsonlog_newline_prepend: bool|null (version >=8.x-1.3 only)
  • jsonlog_tags: comma-separated list; server env var + Drupal conf var

Beware that versions >=8.x-2.* defaults to append newline to log entry instead of prepending.

JSON log fields

  • @timestamp: ISO-8601 milliseconds timestamp instead of watchdog's native seconds timestamp
  • @version: (always) 1
  • message_id: jsonlog site ID + unique padding
  • site_id: (default) server's hostname + database name + database prefix (if any)
  • canonical: name; for site identification across multiple instances (default empty)
  • tags: comma-separated list; becomes array
  • type: always 'drupal'
  • subtype: drupal watchdog type
  • severity: (string) error is 'error', not 3
  • method: HTTP request method, or 'cli' (if drush)
  • request_uri
  • referer
  • uid
  • username: name of current user, or empty (deprecated >=8.x-2.*)
  • client_ip: equivalent to watchdog standard 'ip' field
  • link
  • code: integer if watchdog 'link' is N or 'N'
  • variables: always null, watchdog variables gets parsed into message
  • trunc: null if the log entry as a whole doesn't exceed the json_truncate setting; otherwise array of original length, truncated length


Pros & cons versus dblog and syslog

  • + JSONlog provides Logstash/ElasticSearch-ready and -tailor-made sources; all Logstash has to do is trace files located in standardized directories across multiple servers
  • + dblog may be a performance issue in high traffic environments, due to database operations
  • - but dblog might - due to database writing - be better at handling concurrency
  • + syslog logs all sorts of stuff, not only Drupal site related events
  • + syslog will in most cases truncate at maximally 1Kb; and that size will be unsufficient when logging error traces (for instance via Inspect)


Original concept

and continued source of inspiration: Klavs Klavsen (klavs).

Sponsorship

JSONlog D7 is sponsored by Københavns Kommune, Koncernservice (Copenhagen Municipality, Corporate Services). Recent major versions are sponsored by Cegeka and VDAB.


Documentation (D7)

Requirements

  • D7: PHP 5.3+
  • D9: PHP 7+
  • D10+: PHP 8.1
  • no module dependencies

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Oct 2025
Latest release
10 months ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Slowing

Releases

Version Type Core Release date
4.1.0 Stable 10–11 Oct 1, 2025