Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  

































Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1 Apache Log4j 2  





2 Features  



2.1  Log4j log levels  



2.1.1  Custom log levels  







2.2  Log4j configuration  



2.2.1  Example for Log4j 2  





2.2.2  Example for Log4j 1.2  







2.3  TTCC  







3 Ports  





4 Log4Shell vulnerability  





5 See also  





6 References  





7 Further reading  





8 External links  














Log4j






Català
Čeština
Deutsch
Español
Euskara
فارسی
Français

Italiano
עברית
Magyar
Nederlands

Polski
Português
Română
Русский
کوردی
Türkçe
Українська
Tiếng Vit

 

Edit links
 









Article
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Cite this page
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 




In other projects  



Wikimedia Commons
 
















Appearance
   

 






From Wikipedia, the free encyclopedia
 


Apache Log4j
Developer(s)Apache Software Foundation
Initial releaseJanuary 8, 2001; 23 years ago (2001-01-08)[1]
Stable release

2.23.1[2] Edit this on Wikidata / 10 March 2024; 4 months ago (10 March 2024)[3]

Repositorygithub.com/apache/logging-log4j2
Written inJava
Operating systemCross-platform
TypeLogging
LicenseApache License 2.0
Websitelogging.apache.org/log4j/2.x/

Apache Log4j is a Java-based logging utility originally written by Ceki Gülcü. It is part of the Apache Logging Services, a project of the Apache Software Foundation. Log4j is one of several Java logging frameworks.

Gülcü has since created SLF4J, Reload4j,[4] and Logback[5][better source needed] which are alternatives to Log4j.[6]

The Apache Log4j team developed Log4j 2[7] in response to the problems of Log4j 1.2, 1.3, java.util.logging and Logback, addressing issues which appeared in those frameworks.[8] In addition, Log4j 2 offered a plugin architecture which makes it more extensible than its predecessor. Log4j 2 is not backwards compatible with 1.x versions,[9] although an "adapter" is available. On August 5, 2015, the Apache Logging Services Project Management Committee announced that Log4j 1 had reached end of life and that users of Log4j 1 were advised to upgrade to Apache Log4j 2.[10] On January 12, 2022, a forked and renamed log4j version 1.2 was released by Ceki Gülcü as Reload4j version 1.2.18.0 with the aim of fixing the most urgent issues in log4j 1.2.17 that had accumulated since its release in 2013.[11]

On December 9, 2021, a zero-day vulnerability involving arbitrary code execution in Log4j 2 was published by the Alibaba Cloud Security Team and given the descriptor "Log4Shell".[12] It has been characterized by Tenable as "the single biggest, most critical vulnerability of the last decade".[13]

Apache Log4j 2

[edit]

Apache Log4j 2 is the successor of Log4j 1 which was released as GA version in July 2014. The framework was rewritten from scratch and has been inspired by existing logging solutions, including Log4j 1 and java.util.logging. The main differences[14][15] from Log4j 1 are:

One of the most recognized features of Log4j 2 is the performance of the "Asynchronous Loggers".[16] Log4j 2 makes use of the LMAX Disruptor.[17] The library reduces the need for kernel locking and increases the logging performance by a factor of 12. For example, in the same environment Log4j 2 can write more than 18,000,000 messages per second, whereas other frameworks like Logback and Log4j 1 just write < 2,000,000 messages per second.

Features

[edit]

Log4j log levels

[edit]

The following table defines the built-in log levels and messages in Log4j, in decreasing order of severity. The left column lists the log level designation in Log4j and the right column provides a brief description of each log level.

Level Description
OFF The highest possible rank and is intended to turn off logging.
FATAL Severe errors that cause premature termination. Expect these to be immediately visible on a status console.
ERROR Other runtime errors or unexpected conditions. Expect these to be immediately visible on a status console.
WARN Use of deprecated APIs, poor use of API, 'almost' errors, other runtime situations that are undesirable or unexpected, but not necessarily "wrong". Expect these to be immediately visible on a status console.
INFO Interesting runtime events (startup/shutdown). Expect these to be immediately visible on a console, so be conservative and keep to a minimum.
DEBUG Detailed information on the flow through the system. Expect these to be written to logs only. Generally speaking, most lines logged by your application should be written as DEBUG.
TRACE Most detailed information. Expect these to be written to logs only. Since version 1.2.12.[18]

Custom log levels

[edit]

Log4j 2 allows users to define their own log levels.[19] A source code generator tool is provided to create Loggers that support custom log levels identically to the built-in log levels. Custom log levels can either complement or replace the built-in log levels.

Log4j configuration

[edit]

Log4j can be configured[20] through a configuration file or through Java code. Configuration files can be written in XML, JSON, YAML, or properties file format. Within a configuration, you can define three main components: Loggers, Appenders, and Layouts. Configuring logging via a file has the advantage that logging can be turned on or off without modifying the application that uses Log4j. The application can be allowed to run with logging off until there's a problem, for example, and then logging can be turned back on simply by modifying the configuration file.

Loggers[21] are named log message destinations. They are the names that are known to the Java application. Each logger is independently configurable as to what level of logging (FATAL, ERROR, etc.) it currently logs. In early versions of Log4j, these were called category and priority, but now they're called logger and level, respectively. A Logger can send log messages to multiple Appenders.

The actual outputs are done by Appenders.[22] There are numerous Appenders available, with descriptive names, such as FileAppender, RollingFileAppender, ConsoleAppender, SocketAppender, SyslogAppender, and SMTPAppender. Log4j 2 added Appenders that write to Apache Flume, the Java Persistence API, Apache Kafka, NoSQL databases, Memory-mapped files, Random Access files[23] and ZeroMQ endpoints. Multiple Appenders can be attached to any Logger, so it's possible to log the same information to multiple outputs; for example to a file locally and to a socket listener on another computer.

Appenders use Layouts[24] to format log entries. A popular way to format one-line-at-a-time log files is PatternLayout, which uses a pattern string, much like the C / C++ function printf. There are also HTMLLayout and XMLLayout formatters for use when HTML or XML formats are more convenient, respectively. Log4j 2 added Layouts for CSV, Graylog Extended Log Format (GELF),[25] JSON, YAML and RFC-5424.[26]

In Log4j 2, Filters[27] can be defined on configuration elements to give more fine-grained control over which log entries should be processed by which Loggers and Appenders. In addition to filtering by log level and regular expression matching on the message string, Log4j 2 added burst filters, time filters, filtering by other log event attributes like Markers or Thread Context Map and JSR 223 script filters.

To debug a misbehaving configuration:

To find out where a log4j2.xml configuration file was loaded from inspect getClass().getResource("/log4j2.xml").

There is also an implicit "unconfigured" or "default" configuration of Log4j, that of a Log4j-instrumented Java application which lacks any Log4j configuration. This prints to stdout a warning that the program is unconfigured, and the URL to the Log4j web site where details on the warning and configuration may be found. As well as printing this warning, an unconfigured Log4j application will only print ERROR or FATAL log entries to standard out.

Example for Log4j 2

[edit]
<?xml version="1.0" encoding="UTF-8"?>
<Configuration status="trace" monitorInterval="60">
  <Properties>
    <Property name="filename">target/test.log</Property>
  </Properties>
 
  <Appenders>
    <Console name="STDOUT">
      <PatternLayout pattern="%d %p %c{1.} [%t] %m%n"/>
    </Console>

    <File name="file" fileName="${filename}">
      <PatternLayout>
        <pattern>%d %p %c{1.} [%t] %m%n</pattern>
      </PatternLayout>
    </File>
  </Appenders>
 
  <Loggers> 
    <!-- 
         loggers whose name starts with 'org.springframework' will only log messages of level "info" or higher;
         if you retrieve Loggers by using the class name (e.g. Logger.getLogger(AClass.class))
         and if AClass is part of the org.springframework package, it will belong to this category
    -->
    <Logger name="org.springframework" level="info" additivity="false" />

    <!--
        Filter example: for loggers whose name starts with 'com.mycompany.myproduct',
        log entries of level "debug" or higher whose ThreadContextMap data contains
        the key-value pair "test=123", also send these log entries to the "STDOUT" appender.
    -->
    <Logger name="com.mycompany.myproduct" level="debug" additivity="true">
      <ThreadContextMapFilter>
        <KeyValuePair key="test" value="123"/>
      </ThreadContextMapFilter>
      <AppenderRef ref="STDOUT"/>
    </Logger>
 
    <!--
        By default, all log messages of level "trace" or higher will be logged.
        Log messages are sent to the "file" appender and 
        log messages of level "error" and higher will be sent to the "STDOUT" appender.
    -->
    <Root level="trace">
      <AppenderRef ref="file"/>
      <AppenderRef ref="STDOUT" level="error"/>
    </Root>
  </Loggers>
 
</Configuration>

Example for Log4j 1.2

[edit]
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE log4j:configuration PUBLIC "-//LOGGER" "http://logging.apache.org/log4j/1.2/apidocs/org/apache/log4j/xml/doc-files/log4j.dtd">
<log4j:configuration>
    <!-- 
         an appender is an output destination, such as the console or a file;
         names of appenders are arbitrarily chosen.
    -->
    <appender name="stdout" class="org.apache.log4j.ConsoleAppender">
        <layout class="org.apache.log4j.PatternLayout">
            <param name="ConversionPattern"
                value="%d{ABSOLUTE} %5p %c{1}:%L - %m%n" />
        </layout>
    </appender>
 
    <!-- 
         loggers of category 'org.springframework' will only log messages of level "info" or higher;
         if you retrieve Loggers by using the class name (e.g. Logger.getLogger(AClass.class))
         and if AClass is part of the org.springframework package, it will belong to this category
    -->
    <logger name="org.springframework">
        <level value="info"/>
    </logger>

    <!-- 
         everything of spring was set to "info" but for class 
         PropertyEditorRegistrySupport we want "debug" logging 
    -->
    <logger name="org.springframework.beans.PropertyEditorRegistrySupport">
        <level value="debug"/>
    </logger>
 
    <logger name="org.acegisecurity">
        <level value="info"/>
    </logger>
    
    
    <root>
        <!-- 
            all log messages of level "debug" or higher will be logged, unless defined otherwise 
            all log messages will be logged to the appender "stdout", unless defined otherwise 
        -->
        <level value="debug" />
        <appender-ref ref="stdout" />
    </root>
</log4j:configuration>

TTCC

[edit]

TTCC is a message format used by log4j.[28] TTCC is an acronym for Time Thread Category Component. It uses the following pattern:

 %r [%t] %-5p %c %x - %m%n

Where

Mnemonic Description
%r Used to output the number of milliseconds elapsed from the construction of the layout until the creation of the logging event.
%t Used to output the name of the thread that generated the logging event.
%p Used to output the priority of the logging event.
%c Used to output the category of the logging event.
%x Used to output the NDC (nested diagnostic context) associated with the thread that generated the logging event.[29]
%X{key} Used to output the MDC (mapped diagnostic context) associated with the thread that generated the logging event for specified key.[30]
%m Used to output the application supplied message associated with the logging event.
%n Used to output the platform-specific newline character or characters.

Example output
467 [main] INFO org.apache.log4j.examples.Sort – Exiting main method.

Ports

[edit]

Log4Shell vulnerability

[edit]

Azero-day vulnerability involving remote code execution in Log4j 2, given the descriptor "Log4Shell" (CVE-2021-44228), was found and reported to Apache by Alibaba on November 24, 2021, and published in a tweet on December 9, 2021.[12] Affected services include Cloudflare, iCloud, Minecraft: Java Edition,[42] Steam, Tencent QQ, and Twitter.[43][44][45] The Apache Software Foundation assigned the maximum CVSS severity rating of 10 to Log4Shell, as millions of servers could be potentially vulnerable to the exploit.[45] The vulnerability was characterized by cybersecurity firm Tenable as "the single biggest, most critical vulnerability of the last decade"[13] and Lunasec's Free Wortley characterized it as "a design failure of catastrophic proportions".[46]

In the United States, the director of the Cybersecurity and Infrastructure Security Agency (CISA), Jen Easterly, termed the exploit "critical" and advised vendors to prioritize software updates,[47] and the German agency Federal Office for Information Security (BSI) designated the exploit as being at its highest threat level, calling it an "extremely critical threat situation" (translated).[48][49] The Canadian Centre for Cyber Security (CCCS) called on organisations to take on immediate action.[50]

The feature causing the vulnerability could be disabled with a configuration setting, which had been removed[51] in Log4j version 2.15.0-rc1 (officially released on December 6, 2021, three days before the vulnerability was published), and replaced by various settings restricting remote lookups, thereby mitigating the vulnerability.[52][53] For additional security, all features using JNDI, on which this vulnerability was based, will be disabled by default, and support for message lookups removed from version 2.16.0 onward.[54][55]

See also

[edit]

References

[edit]
  1. ^ "Apache Log4j 1.2 Release History". apache.org. Apache Software Foundation. Retrieved September 2, 2014.
  • ^ "Release 2.23.1". March 10, 2024. Retrieved March 22, 2024.
  • ^ "Release Notes - Log4j". logging.apache.org. Retrieved October 9, 2023.
  • ^ "Reload4j Home". reload4j.qos.ch. Retrieved January 12, 2022.
  • ^ "Logback Home". Logback.qos.ch. Retrieved July 24, 2014.
  • ^ Grigg, Kadi. "Wicked Good Development - Cybersecurity Experts Talk Log4J, Open Source and More". blog.sonatype.com. Retrieved August 16, 2022.
  • ^ "Log4j 2 Guide - Apache Log4j 2". Logging.apache.org. July 12, 2014. Retrieved July 24, 2014.
  • ^ Goers, Ralph (December 15, 2019). "Why was Log4j 2 created?". Ralph Goers.
  • ^ "Log4j 2 Guide - Apache Log4j 2: News". Logging.apache.org. July 12, 2014. Retrieved July 24, 2014.
  • ^ "Apache Logging Services Project Announces Log4j 1 End-Of-Life; Recommends Upgrade to Log4j 2". blogs.apache.org. August 5, 2015. Retrieved July 3, 2016.
  • ^ "Reload4j Project; Easy migration from log4j 1.2.x". qos.ch. January 12, 2022. Retrieved January 12, 2022.
  • ^ a b "What's the Deal with the Log4Shell Security Nightmare?". Lawfare. December 10, 2021.
  • ^ a b "Recently uncovered software flaw 'most critical vulnerability of the last decade'". the Guardian. Associated Press. December 11, 2021.
  • ^ "The new log4j 2.0". Grobmeier.de. December 5, 2012. Retrieved July 24, 2014.
  • ^ "Log4j – Overview - Apache Log4j 2". logging.apache.org. June 5, 2016. Retrieved July 3, 2016.
  • ^ "Log4j 2 Asynchronous Loggers for Low-Latency Logging - Apache Log4j 2". Logging.apache.org. July 12, 2014. Retrieved July 24, 2014.
  • ^ "Disruptor by LMAX-Exchange". Lmax-exchange.github.io. Retrieved July 24, 2014.
  • ^ "Level (Apache Log4j 1.2.17 API)". Logging.apache.org. June 9, 2012. Retrieved July 24, 2014.
  • ^ "Custom Log Levels". Logging.apache.org. July 12, 2014. Retrieved July 16, 2016.
  • ^ "Configuration". Logging.apache.org. July 5, 2016. Retrieved July 16, 2016.
  • ^ "Architecture". Logging.apache.org. July 5, 2016. Retrieved July 16, 2016.
  • ^ "Appenders". Logging.apache.org. July 5, 2016. Retrieved July 16, 2016.
  • ^ "RandomAccessFile". docs.oracle.com. July 28, 2011. Retrieved July 16, 2016.
  • ^ "Layouts". Logging.apache.org. July 5, 2016. Retrieved July 16, 2016.
  • ^ "GELF". docs.graylog.org. June 8, 2016. Archived from the original on February 9, 2020. Retrieved July 16, 2016.
  • ^ Gerhards, R. (March 1, 2009). "RFC 5424 - The Syslog Protocol". tools.ietf.org. doi:10.17487/RFC5424. Retrieved July 16, 2016. {{cite journal}}: Cite journal requires |journal= (help)
  • ^ "Filters". Logging.apache.org. July 5, 2016. Retrieved July 16, 2016.
  • ^ "TTCCLayout (Apache Log4j 1.2.17 API)". Logging.apache.org. June 9, 2012. Retrieved July 24, 2014.
  • ^ "Class NDC". Archived from the original on August 20, 2007. Retrieved December 11, 2021.
  • ^ "MDC (Apache Log4j 1.2.17 API)". Logging.apache.org. June 9, 2012. Retrieved July 24, 2014.
  • ^ "Logging Framework for C | Free System Administration software downloads at". Sourceforge.net. Retrieved July 24, 2014.
  • ^ "stritti/Log4js - The Logging Framework for JavaScript with no runtime dependencies". GitHub. Retrieved December 11, 2021.
  • ^ "a JavaScript logging framework". log4javascript. Retrieved December 11, 2021.
  • ^ "Logging JavaScript errors to your server side log". JSNLog. Retrieved December 11, 2021.
  • ^ "Apache log4net". Logging.apache.org. Retrieved December 11, 2021.
  • ^ Schilli, Mike; Goess, Kevin. "log4perl - log4j for Perl". log4perl. Retrieved December 11, 2021.
  • ^ "Apache Logging Services". Apache.org. Retrieved March 11, 2015.
  • ^ "tmuth/Logger-A-PL-SQL-Logging-Utility — GitHub". Github.com. Retrieved July 24, 2014.
  • ^ "Log4db2 by angoca". Angoca.github.io. Retrieved July 24, 2014.
  • ^ "log4cxx - Changelog". logging.apache.org.
  • ^ "Log4r Manual". log4r.rubyforge.org. Archived from the original on December 25, 2012. Retrieved April 13, 2017.
  • ^ "Security Vulnerability in Minecraft: Java Edition". Minecraft. December 10, 2021.
  • ^ Goodin, Dan (December 9, 2021). "Zeroday in ubiquitous Log4j tool poses a grave threat to the Internet". Ars Technica. Retrieved December 10, 2021.
  • ^ "Worst Apache Log4j RCE Zero day Dropped on Internet". Cyber Kendra. December 9, 2021. Retrieved December 10, 2021.
  • ^ a b Mott, Nathaniel (December 10, 2021). "Countless Servers Are Vulnerable to Apache Log4j Zero-Day Exploit". PC Magazine. Retrieved December 10, 2021.
  • ^ Newman, Lily Hay (December 10, 2021). "The Internet Is on Fire". Wired – via www.wired.com.
  • ^ "Statement from CISA Director Easterly on "Log4j" Vulnerability". CISA. Washington. December 11, 2021.
  • ^ "BSI warnt vor Sicherheitslücke" [BSI warns of security vulnerabilities]. Tagesschau (in German). December 12, 2021.
  • ^ "Warnstufe Rot: Schwachstelle Log4Shell führt zu extrem kritischer Bedrohungslage" [Red alarm: Log4Shell vulnerability causes extremely critical threat situation]. BSI press service (in German). December 12, 2021.
  • ^ "Statement from the Minister of National Defence on Apache Vulnerability and Call to Canadian Organizations to Take Urgent Action". Government of Canada. December 12, 2021. Archived from the original on December 20, 2021. Retrieved December 12, 2021.
  • ^ "LOG4J2-3198: Log4j2 no longer formats lookups in messages by default". GitHub. December 5, 2021.
  • ^ "Restrict LDAP access via JNDI by rgoers · Pull Request #608 · apache/logging-log4j2". GitHub. 30 November–5 December 2021
  • ^ "Apache Log4j Security Vulnerabilities". December 6, 2021.
  • ^ "LOG4J2-3208: Disable JNDI by default". December 11, 2021. Retrieved December 14, 2021.
  • ^ "LOG4J2-3211: Remove support for Lookups in messages". December 13, 2021. Retrieved December 14, 2021.
  • Further reading

    [edit]
    • Gülcü, Ceki (February 2010), The Complete Log4j Manual (2nd ed.), QOS.ch, p. 204, ISBN 978-2-9700369-0-6
  • Gupta, Samudra (June 22, 2005), Pro Apache Log4j (2nd ed.), Apress, p. 224, ISBN 978-1-59059-499-5
  • [edit]
    Retrieved from "https://en.wikipedia.org/w/index.php?title=Log4j&oldid=1230768614"

    Categories: 
    Apache Software Foundation
    Free software programmed in Java (programming language)
    Log file formats
    Software using the Apache license
    Hidden categories: 
    CS1 errors: missing periodical
    CS1 German-language sources (de)
    Articles with short description
    Short description is different from Wikidata
    Use mdy dates from December 2021
    Use American English from December 2021
    All Wikipedia articles written in American English
    All articles lacking reliable references
    Articles lacking reliable references from August 2022
    Articles containing potentially dated statements from 2021
    All articles containing potentially dated statements
    Articles containing potentially dated statements from 2022
    Articles containing potentially dated statements from 2024
     



    This page was last edited on 24 June 2024, at 16:07 (UTC).

    Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



    Privacy policy

    About Wikipedia

    Disclaimers

    Contact Wikipedia

    Code of Conduct

    Developers

    Statistics

    Cookie statement

    Mobile view



    Wikimedia Foundation
    Powered by MediaWiki