Self-Hosted Platform Administration
Logging, diagnostics, alerts, and privacy controls
Review operator-facing logs, alerts, and organization diagnostics while protecting sensitive data.
Review logs, alerts, and audit activity as part of normal platform operations. The maintenance log is available at /var/lib/sigora/logs/maintenance.log by default. Apache logs are available under /var/log/apache2/. Your deployment can use a different maintenance-log location through the supported environment setting.
Platform alerts and audit logs are separate from organization alerts and audit logs. Review retention settings against your legal, contractual, and incident-response requirements before scheduling cleanup activities.
Collect organization diagnostics
Authorized platform operators can set the detail level for an organization’s non-identifying logs and request a collection from active Nodes. Use the lowest detail level that can answer the operational question. Temporary info or debug collection should have a short, defined duration and should be reviewed in the audit log.
When requesting a collection:
- Confirm the affected organization and the minimum time period needed.
- Tell the organization administrator what will be collected and why.
- Restrict access to the resulting archive.
- Download and retain the archive only according to the organization’s approved policy.
- Remove local copies when the investigation is complete.
Protect high-risk diagnostic data
Organization administrators, not platform operators, enable temporary identifiable logging or full message dumps from organization preferences.
Ensure that the Node account can write to the configured diagnostic directories and that those directories are protected from other users on the host. Monitor available storage while diagnostics are enabled. Follow the organization’s retention policy when removing collected archives and downloaded copies.