События системного журнала#

Прокси сервер (Nginx)#

Состояние сервиса:

systemctl status nginx

Логи запросов к IAM Proxy#

/usr/local/openresty/nginx/logs/access.log

[09/Apr/2020:17:36:03 +0300] 10.x.x.63:36350 -> 10.x.x.178:45406 -> 10.x.x.162:10444 -> - - - "GET /sps-st/sps/admin/index;jsessionid=7pthWVu2FYn5OxeP3GokVZaSem7ST5bvT4tmvyGW.tkli-ppr2788 HTTP/1.1" 302 153 "https://platform-devb.mycompany.ru/" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 YaBrowser/19.x.x.281 Yowser/2.5 Safari/537.36" "-"
[09/Apr/2020:17:36:03 +0300] 10.x.x.63:36350 -> 10.x.x.178:45406 -> 10.x.x.162:10444 -> - - - "GET /openid-connect-auth/redirect_uri?state=901af43b699cc0936418a48ce27c2bec&session_state=89c4632a-6ada-4a3e-9d88-c1e221b28483&code=07e81bac-73d7-482e-be05-68a4f7310e78.89c4632a-6ada-4a3e-9d88-c1e221b28483.e330def0-182f-4d93-8887-97928f014dc4 HTTP/1.1" 302 142 "https://platform-devb.mycompany.ru/" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 YaBrowser/19.x.x.281 Yowser/2.5 Safari/537.36" "-"
[09/Apr/2020:17:36:04 +0300] 10.x.x.63:36350 -> 10.x.x.178:45406 -> 10.x.x.162:10444 -> 10.x.x.149:8443 - sudir-admin "GET /sps-st/sps/admin/index;jsessionid=7pthWVu2FYn5OxeP3GokVZaSem7ST5bvT4tmvyGW.tkli-ppr2788 HTTP/1.1" 200 8357 "https://platform-devb.mycompany.ru/" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 YaBrowser/19.x.x.281 Yowser/2.5 Safari/537.36" "-"
[09/Apr/2020:17:36:04 +0300] 10.x.x.63:36350 -> 10.x.x.178:45406 -> 10.x.x.162:10444 -> 10.x.x.149:8443 - sudir-admin "GET /sps-st/sps/ext/resources/css/as.css HTTP/1.1" 200 33128 "https://platform-devb.mycompany.ru/sps-st/sps/admin/index;jsessionid=7pthWVu2FYn5OxeP3GokVZaSem7ST5bvT4tmvyGW.tkli-ppr2788" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 YaBrowser/19.x.x.281 Yowser/2.5 Safari/537.36" "-"
[09/Apr/2020:17:36:04 +0300] 10.x.x.63:36350 -> 10.x.x.178:45406 -> 10.x.x.162:10444 -> 10.x.x.149:8443 - sudir-admin "GET /sps-st/sps/ext/resources/ext-theme-neptune/ext-theme-neptune-all.css HTTP/1.1" 200 318552 "https://platform-devb.mycompany.ru/sps-st/sps/admin/index;jsessionid=7pthWVu2FYn5OxeP3GokVZaSem7ST5bvT4tmvyGW.tkli-ppr2788" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 YaBrowser/19.x.x.281 Yowser/2.5 Safari/537.36" "-"
[09/Apr/2020:17:36:04 +0300] 10.x.x.63:36362 -> 10.x.x.178:45436 -> 10.x.x.162:10444 -> 10.x.x.149:8443 - sudir-admin "GET /sps-st/sps/ext/App/Api.js HTTP/1.1" 200 3210 "https://platform-devb.mycompany.ru/sps-st/sps/admin/index;jsessionid=7pthWVu2FYn5OxeP3GokVZaSem7ST5bvT4tmvyGW.tkli-ppr2788" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 YaBrowser/19.x.x.281 Yowser/2.5 Safari/537.36" "-"
[09/Apr/2020:17:36:04 +0300] 10.x.x.63:36368 -> 10.x.x.178:45448 -> 10.x.x.162:10444 -> 10.x.x.149:8443 - sudir-admin "GET /sps-st/sps/ext/App/ux/UX_DateTimeField.js HTTP/1.1" 200 1367 "https://platform-devb.mycompany.ru/sps-st/sps/admin/index;jsessionid=7pthWVu2FYn5OxeP3GokVZaSem7ST5bvT4tmvyGW.tkli-ppr2788" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 YaBrowser/19.x.x.281 Yowser/2.5 Safari/537.36" "-"

Логи ошибок и других диагностических сообщений (детализация зависит от уровня логирования в nginx.conf)#

/usr/local/openresty/nginx/logs/error.log

2020/04/09 17:15:43 [warn] 2090#2090: the "user" directive makes sense only if the master process runs with super-user privileges, ignored in /usr/local/openresty/nginx/conf/nginx.conf:2
2020/04/09 17:15:47 [warn] 2322#2322: the "user" directive makes sense only if the master process runs with super-user privileges, ignored in /usr/local/openresty/nginx/conf/nginx.conf.rds:2
2020/04/09 17:15:47 [warn] 2356#2356: the "user" directive makes sense only if the master process runs with super-user privileges, ignored in /usr/local/openresty/nginx/conf/nginx.conf.rds:2
2020/04/09 17:36:03 [error] 2385#2385: send() failed (111: Connection refused)
2020/04/09 17:36:04 [crit] 2385#2385: *7 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:04 [crit] 2385#2385: *9 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:04 [crit] 2384#2384: *8 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:04 [crit] 2385#2385: *10 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:04 [crit] 2384#2384: *11 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:04 [crit] 2384#2384: *19 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:04 [crit] 2385#2385: *18 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:04 [crit] 2385#2385: *20 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:04 [crit] 2385#2385: *22 SSL_do_handshake() failed (SSL: error:140944E7:SSL routines:ssl3_read_bytes:reason(1255):SSL alert number 255) while SSL handshaking, client: 10.x.x.178, server: 0.0.0.0:10444
2020/04/09 17:36:05 [error] 2385#2385: send() failed (111: Connection refused)

Изменение уровня логирования на самый подробный производится опцией в nginx.conf

error_log logs/error.log debug;

Клиент по конфигурированию маршрутов (rds-client)#

состояние сервиса:

systemctl status rds-client

логи работы приложения
/usr/local/openresty/nginx/rds-client/logs/log-2020-04-10.log

16:35:15.096  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:15.105  INFO | [pool-3-thread-1]: Response received.
16:35:20.097  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:20.116  INFO | [pool-3-thread-1]: Response received.
16:35:25.097  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:25.104  INFO | [pool-3-thread-1]: Response received.
16:35:29.823  INFO | [main]: RDS-client is started
16:35:30.287  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/last-conf.json
16:35:30.375  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.498  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/index.html
16:35:30.537  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.546  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/sps-st.upstream.conf
16:35:30.550  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.552  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/spsSt.upstream.conf
16:35:30.556  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.558  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/prb-st.upstream.conf
16:35:30.562  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.566  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/prb-st2.upstream.conf
16:35:30.567  INFO | [pool-1-thread-1]: Name for resulting file is empty. Skip. [/usr/local/openresty/nginx/rds-client/templates/jct.name-upstream.upstream.jinja2 , jct]
16:35:30.571  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.574  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/aud-st.upstream.conf
16:35:30.576  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.578  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/logger-st.upstream.conf
16:35:30.581  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.583  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/rds-for-proxy.upstream.conf
16:35:30.586  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.589  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/jct-snoop.upstream.conf
16:35:30.591  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.595  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/snoop.upstream.conf
16:35:30.597  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.600  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/stub.upstream.conf
16:35:30.602  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.604  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/test-sutb2.upstream.conf
16:35:30.607  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.613  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/sps-st.server.conf
16:35:30.615  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.618  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/spsSt.server.conf
16:35:30.626  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.628  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/prb-st.server.conf
16:35:30.631  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.634  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/prb-st2.server.conf
16:35:30.641  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.643  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/logger-st.server.conf
16:35:30.648  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.651  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/aud-st.server.conf
16:35:30.653  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.656  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/logger-st.server.conf
16:35:30.659  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.661  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/rds-for-proxy.server.conf
16:35:30.664  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.667  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/jct-snoop.server.conf
16:35:30.669  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.672  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/snoop.server.conf
16:35:30.674  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.678  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/stub.server.conf
16:35:30.680  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.682  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/results/test-sutb2.server.conf
16:35:30.685  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/context.log
16:35:30.687  INFO | [pool-1-thread-1]: Write to file: /usr/local/openresty/nginx/rds-client/cache/reload-nginx.sh
16:35:30.792  INFO | [pool-1-thread-1]:  --- SCRIPT OUTPUT BEGIN --- 
16:35:30.793  INFO | [pool-1-thread-1]: nginx: [warn] the "user" directive makes sense only if the master process runs with super-user privileges, ignored in /usr/local/openresty/nginx/conf/nginx.conf.rds:2
16:35:30.793  INFO | [pool-1-thread-1]: OK - Тест новой конфигурации пройден
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/test-sutb2.server.conf -> /usr/local/openresty/nginx/conf/jct/test-sutb2.server.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/stub.server.conf -> /usr/local/openresty/nginx/conf/jct/stub.server.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/sps-st.upstream.conf -> /usr/local/openresty/nginx/conf/jct/sps-st.upstream.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/spsSt.upstream.conf -> /usr/local/openresty/nginx/conf/jct/spsSt.upstream.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/logger-st.server.conf -> /usr/local/openresty/nginx/conf/jct/logger-st.server.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/aud-st.upstream.conf -> /usr/local/openresty/nginx/conf/jct/aud-st.upstream.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/snoop.server.conf -> /usr/local/openresty/nginx/conf/jct/snoop.server.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/snoop.upstream.conf -> /usr/local/openresty/nginx/conf/jct/snoop.upstream.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/jct-snoop.server.conf -> /usr/local/openresty/nginx/conf/jct/jct-snoop.server.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/prb-st2.upstream.conf -> /usr/local/openresty/nginx/conf/jct/prb-st2.upstream.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.793  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/aud-st.server.conf -> /usr/local/openresty/nginx/conf/jct/aud-st.server.conf
16:35:30.793  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/rds-for-proxy.server.conf -> /usr/local/openresty/nginx/conf/jct/rds-for-proxy.server.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/stub.upstream.conf -> /usr/local/openresty/nginx/conf/jct/stub.upstream.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/sps-st.server.conf -> /usr/local/openresty/nginx/conf/jct/sps-st.server.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/logger-st.upstream.conf -> /usr/local/openresty/nginx/conf/jct/logger-st.upstream.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/jct-snoop.upstream.conf -> /usr/local/openresty/nginx/conf/jct/jct-snoop.upstream.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/prb-st.server.conf -> /usr/local/openresty/nginx/conf/jct/prb-st.server.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/prb-st.upstream.conf -> /usr/local/openresty/nginx/conf/jct/prb-st.upstream.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/rds-for-proxy.upstream.conf -> /usr/local/openresty/nginx/conf/jct/rds-for-proxy.upstream.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/test-sutb2.upstream.conf -> /usr/local/openresty/nginx/conf/jct/test-sutb2.upstream.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/spsSt.server.conf -> /usr/local/openresty/nginx/conf/jct/spsSt.server.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: /usr/local/openresty/nginx/rds-client/results/prb-st2.server.conf -> /usr/local/openresty/nginx/conf/jct/prb-st2.server.conf
16:35:30.794  INFO | [pool-1-thread-1]: ok
16:35:30.794  INFO | [pool-1-thread-1]: ‘/usr/local/openresty/nginx/rds-client/results/index.html’ -> ‘/usr/local/openresty/nginx/conf/../html/index.html’
16:35:30.794  INFO | [pool-1-thread-1]: Успешно запущен reload nginx [31147]
16:35:30.794  INFO | [pool-1-thread-1]:  --- SCRIPT OUTPUT END --- 
16:35:30.796  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:30.945  INFO | [pool-3-thread-1]: *** SSL *** Force set private key with alias: platform-devb.mycompany.ru
16:35:31.076  INFO | [pool-3-thread-1]: Response received.
16:35:35.796  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:35.812  INFO | [pool-3-thread-1]: Response received.
16:35:40.797  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:40.812  INFO | [pool-3-thread-1]: Response received.
16:35:45.797  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:45.809  INFO | [pool-3-thread-1]: Response received.
16:35:50.797  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:50.811  INFO | [pool-3-thread-1]: Response received.
16:35:55.797  INFO | [pool-3-thread-1]: Trying to send GET request to https://mycompany-auth-svc-idp1-dev2.mycompany.ru:7443/rds-for-proxy/active-conf-json
16:35:55.809  INFO | [pool-3-thread-1]: Response received.

При использовании nginx как программного балансировщика#

Состояние сервиса:

systemctl status lb-nginx

Расположение логов:

/usr/local/openresty/nginx/lb-logs/access-lb-nginx.log

/usr/local/openresty/nginx/lb-logs/error-lb-nginx.log

Сервер аутентификации (Keycloak)#

Состояние сервиса:

systemctl status keycloak

Логи java#

/opt/keycloak-4.8.3.Final/standalone/log/server.log

2020-04-09 14:27:23,362 WARN  [org.keycloak.events] (default task-2) type=LOGIN_ERROR, realmId=master, clientId=security-admin-console, userId=712a734e-0750-489e-bac4-fda968d43be8, ipAddress=10.x.x.63, error=invalid_user_credentials, auth_method=openid-connect, auth_type=code, redirect_uri=https://10.x.x.178:8444/auth/admin/master/console/, code_id=f30ebc76-3f9f-49d4-baff-75dc2ec55939, username=admin
2020-04-09 14:27:23,395 WARN  [org.keycloak.services] (Brute Force Protector) KC-SERVICES0053: login failure for user 712a734e-0750-489e-bac4-fda968d43be8 from ip 10.x.x.63
2020-04-09 14:27:26,568 WARN  [org.keycloak.events] (default task-2) type=LOGIN_ERROR, realmId=master, clientId=security-admin-console, userId=712a734e-0750-489e-bac4-fda968d43be8, ipAddress=10.x.x.63, error=invalid_user_credentials, auth_method=openid-connect, auth_type=code, redirect_uri=https://10.x.x.178:8444/auth/admin/master/console/, code_id=f30ebc76-3f9f-49d4-baff-75dc2ec55939, username=admin
2020-04-09 14:27:26,579 WARN  [org.keycloak.services] (Brute Force Protector) KC-SERVICES0053: login failure for user 712a734e-0750-489e-bac4-fda968d43be8 from ip 10.x.x.63
2020-04-09 14:30:56,725 WARN  [org.keycloak.events] (default task-5) type=LOGIN_ERROR, realmId=PlatformAuth, clientId=PlatformAuth-Proxy, userId=a13c334e-b538-4706-80de-6065a68c0edc, ipAddress=10.x.x.180, error=invalid_user_credentials, auth_method=openid-connect, auth_type=code, redirect_uri=https://platform-devb.mycompany.ru/openid-connect-auth/redirect_uri, code_id=89c4632a-6ada-4a3e-9d88-c1e221b28483, username=sudir-admin
2020-04-09 14:30:56,751 WARN  [org.keycloak.services] (Brute Force Protector) KC-SERVICES0053: login failure for user a13c334e-b538-4706-80de-6065a68c0edc from ip 10.x.x.180

Сервер обработки логов (Syslog-NG)#

Посмотреть состояние сервиса, команда:

systemctl status syslog-ng

логи сервиса в /var/log/messages

Логи модуля java#

/var/log/syslog-ng/java.log

2020-04-03 01:47:29,387 INFO  [root] - sendToAudit: logMessage=org.syslog_ng.LogMessage@41cae424
2020-04-03 01:47:29,390 DEBUG [root] - doAudit r=com.sbt.ppr.platformauth.syslogng.audit2.AuditDestination$$Lambda$58/99663809@11419d1a
2020-04-03 01:47:29,391 DEBUG [root] - sendToAudit: fieldValues={action=[keycloak,authn,oidc] Аутентификация пользователя, fullhost=mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru, isodate=2020-04-02T22:47:29+00:00, authn.realmId=master, authn.event_type=LOGIN, authn.userId=712a734e-0750-489e-bac4-fda968d43be8, authn.userName=admin, authn.ipAddress=10.x.x.63, authn.oidc.clientId=security-admin-console, authn.oidc.auth_method=openid-connect / code, authn.oidc.redirect_uri=https://10.x.x.178:8444/auth/admin/master/console/#/realms/PlatformAuth/identity-provider-settings}
2020-04-03 01:47:29,391 DEBUG [root] - doAudit r=com.sbt.ppr.platformauth.syslogng.audit2.AuditDestination$$Lambda$52/500746777@20e1d564
2020-04-03 01:47:29,393 DEBUG [root] - doAudit OK, operation=com.sbt.audit2.OperationHandlerImpl@c77d85
2020-04-03 01:47:29,393 DEBUG [root] - sendToAudit: calling auditUserEvent with pars=[UserEventParam{name='action', value='[keycloak,authn,oidc] Аутентификация пользователя', linkedEntityID=null}, UserEventParam{name='fullhost', value='mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru', linkedEntityID=null}, UserEventParam{name='isodate', value='2020-04-02T22:47:29+00:00', linkedEntityID=null}, UserEventParam{name='authn.realmId', value='master', linkedEntityID=null}, UserEventParam{name='authn.event_type', value='LOGIN', linkedEntityID=null}, UserEventParam{name='authn.userId', value='712a734e-0750-489e-bac4-fda968d43be8', linkedEntityID=null}, UserEventParam{name='authn.userName', value='admin', linkedEntityID=null}, UserEventParam{name='authn.ipAddress', value='10.x.x.63', linkedEntityID=null}, UserEventParam{name='authn.oidc.clientId', value='security-admin-console', linkedEntityID=null}, UserEventParam{name='authn.oidc.auth_method', value='openid-connect / code', linkedEntityID=null}, UserEventParam{name='authn.oidc.redirect_uri', value='https://10.x.x.178:8444/auth/admin/master/console/#/realms/PlatformAuth/identity-provider-settings', linkedEntityID=null}]
2020-04-03 01:47:29,393 DEBUG [root] - sendToAudit: called auditUserEvent, committing
2020-04-03 01:47:29,393 DEBUG [root] - doAudit OK, operation=com.sbt.audit2.OperationHandlerImpl@c77d85
2020-04-03 01:47:29,393 DEBUG [root] - sendToAudit delay=6.372634ms
2020-04-03 01:47:30,365 INFO  [root] - sendToAudit: logMessage=org.syslog_ng.LogMessage@16ba527d
2020-04-03 01:47:30,365 DEBUG [root] - doAudit r=com.sbt.ppr.platformauth.syslogng.audit2.AuditDestination$$Lambda$58/99663809@b0ea4fd
2020-04-03 01:47:30,365 DEBUG [root] - sendToAudit: fieldValues={action=[keycloak,authn,oidc] Аутентификация пользователя, fullhost=mycompany-auth-svc-idp1-devb.vm.mos.mycompany.ru, isodate=2020-04-02T22:47:30+00:00, authn.realmId=master, authn.event_type=CODE_TO_TOKEN, authn.userId=712a734e-0750-489e-bac4-fda968d43be8, authn.userName=admin, authn.ipAddress=10.x.x.63, authn.oidc.clientId=security-admin-console, authn.oidc.auth_method= / , authn.oidc.redirect_uri=}
2020-04-03 01:47:30,365 DEBUG [root] - doAudit r=com.sbt.ppr.platformauth.syslogng.audit2.AuditDestination$$Lambda$52/500746777@256a0a0d
2020-04-03 01:47:30,366 DEBUG [root] - doAudit OK, operation=com.sbt.audit2.OperationHandlerImpl@1e7a6070
2020-04-03 01:47:30,366 DEBUG [root] - sendToAudit: calling auditUserEvent with pars=[UserEventParam{name='action', value='[keycloak,authn,oidc] Аутентификация пользователя', linkedEntityID=null}, UserEventParam{name='fullhost', value='mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru', linkedEntityID=null}, UserEventParam{name='isodate', value='2020-04-02T22:47:30+00:00', linkedEntityID=null}, UserEventParam{name='authn.realmId', value='master', linkedEntityID=null}, UserEventParam{name='authn.event_type', value='CODE_TO_TOKEN', linkedEntityID=null}, UserEventParam{name='authn.userId', value='712a734e-0750-489e-bac4-fda968d43be8', linkedEntityID=null}, UserEventParam{name='authn.userName', value='admin', linkedEntityID=null}, UserEventParam{name='authn.ipAddress', value='10.x.x.63', linkedEntityID=null}, UserEventParam{name='authn.oidc.clientId', value='security-admin-console', linkedEntityID=null}, UserEventParam{name='authn.oidc.auth_method', value=' / ', linkedEntityID=null}, UserEventParam{name='authn.oidc.redirect_uri', value='', linkedEntityID=null}]
2020-04-03 01:47:30,366 DEBUG [root] - sendToAudit: called auditUserEvent, committing
2020-04-03 01:47:30,366 DEBUG [root] - doAudit OK, operation=com.sbt.audit2.OperationHandlerImpl@1e7a6070
2020-04-03 01:47:30,366 DEBUG [root] - sendToAudit delay=1.952938ms

Логи принятых сообщений от keycloak#

/var/log/syslog-ng/keycloak_logs_tls.log

Dec 13 11:41:57 mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru send-events-to-syslog: type=LOGIN_ERROR, realmId=PlatformAuth, clientId=PlatformAuth-Proxy, userId=, ipAddress="10.x.x.180", error=invalid_redirect_uri, redirect_uri="https://10.x.x.59:32826/openid-connect-auth/redirect_uri"
Dec 13 15:07:58 mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru send-events-to-syslog: type=LOGIN, realmId=master, clientId=security-admin-console, userId=712a734e-0750-489e-bac4-fda968d43be8, ipAddress="10.x.x.60", auth_method=openid-connect, auth_type=code, redirect_uri="https://10.x.x.178:8444/auth/admin/master/console/", consent=no_consent_required, code_id=5a3f03bb-d8eb-4280-85bc-ac4ab182f335, username=admin
Dec 13 15:09:27 mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru send-events-to-syslog: type=REFRESH_TOKEN, realmId=master, clientId=security-admin-console, userId=712a734e-0750-489e-bac4-fda968d43be8, ipAddress="10.x.x.60", token_id=1cbe88c9-d34e-4546-ad37-248334c1c2b2, grant_type=refresh_token, refresh_token_type=Refresh, updated_refresh_token_id=da2531ff-0631-4175-9258-06f893098cd2, scope="openid profile email", refresh_token_id=891c6ac6-d238-46d7-b386-e716dfc1a0a6, client_auth_method=client-secret
Dec 13 15:12:36 mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru send-events-to-syslog: type=REFRESH_TOKEN, realmId=master, clientId=security-admin-console, userId=712a734e-0750-489e-bac4-fda968d43be8, ipAddress="10.x.x.60", token_id=25d1f35b-450d-41df-a74d-e392fbe0b171, grant_type=refresh_token, refresh_token_type=Refresh, updated_refresh_token_id=4ae520b1-ef77-42a7-b2f3-214210b56ba7, scope="openid profile email", refresh_token_id=da2531ff-0631-4175-9258-06f893098cd2, client_auth_method=client-secret
Dec 13 15:13:13 mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru send-events-to-syslog: operationType=UPDATE, realmId=master, clientId=97944ae7-2b78-41c5-91d2-85a8a04bb1b0, userId=712a734e-0750-489e-bac4-fda968d43be8, ipAddress="10.x.x.60", resourcePath="clients/e330def0-182f-4d93-8887-97928f014dc4", data="{\"id\":\"e330def0-182f-4d93-8887-97928f014dc4\",\"clientId\":\"PlatformAuth-Proxy\",\"name\":\"Platform V (Сервис аутентификации)\",\"description\":\"Аутентификация на прокси сервере сервиса аутентификации платформы\",\"baseUrl\":\"https://platform-devb.mycompany.ru/\",\"surrogateAuthRequired\":false,\"enabled\":true,\"clientAuthenticatorType\":\"client-secret\",\"redirectUris\":[\"https://platform-devb.mycompany.ru/*\",\"https://10.x.x.180:10443/*\",\"https://10.x.x.162:10443/*\",\"https://10.x.x.59:*\"],\"webOrigins\":[\"+\"],\"notBefore\":0,\"bearerOnly\":false,\"consentRequired\":false,\"standardFlowEnabled\":true,\"implicitFlowEnabled\":false,\"directAccessGrantsEnabled\":false,\"serviceAccountsEnabled\":false,\"publicClient\":false,\"frontchannelLogout\":false,\"protocol\":\"openid-connect\",\"attributes\":{\"saml.assertion.signature\":\"false\",\"saml.force.post.binding\":\"false\",\"saml.multivalued.roles\":\"false\",\"saml.encrypt\":\"false\",\"access.token.signed.response.alg\":\"\",\"saml.server.signature\":\"false\",\"saml.server.signature.keyinfo.ext\":\"false\",\"exclude.session.state.from.auth.response\":\"false\",\"id.token.signed.response.alg\":\"\",\"saml_force_name_id_format\":\"false\",\"saml.client.signature\":\"false\",\"tls.client.certificate.bound.access.tokens\":\"false\",\"saml.authnstatement\":\"false\",\"display.on.consent.screen\":\"false\",\"saml.onetimeuse.condition\":\"false\"},\"authenticationFlowBindingOverrides\":{},\"fullScopeAllowed\":false,\"nodeReRegistrationTimeout\":-1,\"protocolMappers\":[{\"id\":\"425503f1-a623-4308-b50a-2cec5694b445\",\"name\":\"Платформа, сервис авторизации (sps)\",\"protocol\":\"openid-connect\",\"protocolMapper\":\"oidc-audience-mapper\",\"consentRequired\":false,\"config\":{\"id.token.claim\":\"true\",\"access.token.claim\":\"false\",\"included.custom.audience\":\"PlatformAuthZ\",\"userinfo.token.claim\":\"true\"}},{\"id\":\"29eb2905-b9b8-4f1e-a67a-a51c439e69ee\",\"name\":\"Платформа, Азимут\",\"protocol\":\"openid-connect\",\"protocolMapper\":\"oidc-audience-mapper\",\"consentRequired\":false,\"config\":{\"id.token.claim\":\"true\",\"access.token.claim\":\"false\",\"included.custom.audience\":\"PlatformAzimuth\",\"userinfo.token.claim\":\"true\"}},{\"id\":\"e12309a3-a723-49a7-a06c-da101d4f88b4\",\"name\":\"Платформа, BGP\",\"protocol\":\"openid-connect\",\"protocolMapper\":\"oidc-audience-mapper\",\"consentRequired\":false,\"config\":{\"id.token.claim\":\"true\",\"access.token.claim\":\"false\",\"included.custom.audience\":\"PlatformBGP\",\"userinfo.token.claim\":\"true\"}}],\"defaultClientScopes\":[\"role_list\",\"login\"],\"optionalClientScopes\":[\"address\",\"phone\",\"roles\",\"profile\",\"email\"],\"access\":{\"view\":true,\"configure\":true,\"manage\":true}}"
Dec 13 15:16:05 mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru send-events-to-syslog: type=REFRESH_TOKEN, realmId=master, clientId=security-admin-console, userId=712a734e-0750-489e-bac4-fda968d43be8, ipAddress="10.x.x.60", token_id=b815c211-7ddb-49e1-9f42-7f01ef380594, grant_type=refresh_token, refresh_token_type=Refresh, updated_refresh_token_id=2a098ba7-905f-43d9-9f31-465f27fd8970, scope="openid profile email", refresh_token_id=4ae520b1-ef77-42a7-b2f3-214210b56ba7, client_auth_method=client-secret
Dec 13 15:18:55 mycompany-auth-svc-idp1-devb.vm.mos.cloud.mycompany.ru send-events-to-syslog: type=LOGIN, realmId=PlatformAuth, clientId=PlatformAuth-Proxy, userId=eeaac123-b027-4cb9-af14-cb86363ed921, ipAddress="10.x.x.180", auth_method=openid-connect, auth_type=code, redirect_uri="https://10.x.x.59:32826/openid-connect-auth/redirect_uri", consent=no_consent_required, code_id=e66694ac-7a10-4866-bf16-0b88ad5c74f8, username=test_user

Логи принятых сообщений от nginx#

/var/log/syslog-ng/nginx_logs.log

Apr  3 03:12:22 mycompany-auth-svc-proxy1-devb nginx: BR:"GET /openid-connect-auth/redirect_uri?state=2b39050bb5e25eb2a00ee177e2784e35&session_state=5389fb52-917d-4fef-9ffc-75de77d7c805&code=be0a89c7-fb9f-4506-b4a2-5516be0165f1.5389fb52-917d-4fef-9ffc-75de77d7c805.e330def0-182f-4d93-8887-97928f014dc4 HTTP/1.1" TS:2020-04-03T03:12:22+03:00 M:GET URL:"/openid-connect-auth/redirect_uri?state=2b39050bb5e25eb2a00ee177e2784e35&session_state=5389fb52-917d-4fef-9ffc-75de77d7c805&code=be0a89c7-fb9f-4506-b4a2-5516be0165f1.5389fb52-917d-4fef-9ffc-75de77d7c805.e330def0-182f-4d93-8887-97928f014dc4" CA:10.x.x.178[10.x.x.63] F:0.078 ST:302 B:142 CTRESP:"text/html" SI:- SU:- LA:10.x.x.162 JN: S:- T:87f28b015aaa9f0ea953d1ba5d9f3b42
Apr  3 03:12:22 mycompany-auth-svc-proxy1-devb nginx: BR:"GET / HTTP/1.1" TS:2020-04-03T03:12:22+03:00 M:GET URL:"/" CA:10.x.x.178[10.x.x.63] F:0.000 ST:200 B:12336 CTRESP:"text/html; charset=utf-8" SI:001b5df6de8c4bcfaa9d02d1dba01e72 SU:admin LA:10.x.x.162 JN: S:- T:5ce4cafd9f943d8ffa66623d94547a04
Apr  3 03:12:30 mycompany-auth-svc-proxy1-devb nginx: BR:"GET /jwt/ HTTP/1.1" TS:2020-04-03T03:12:30+03:00 M:GET URL:"/jwt/" CA:10.x.x.178[10.x.x.63] F:0.000 ST:200 B:6771 CTRESP:"text/html" SI:001b5df6de8c4bcfaa9d02d1dba01e72 SU:admin LA:10.x.x.162 JN: S:- T:201d2b6039b159003d5d1e6d87cb49bc
Apr  3 03:20:24 mycompany-auth-svc-proxy1-devb nginx: BR:"GET /openid-connect-auth/logout HTTP/1.1" TS:2020-04-03T03:20:24+03:00 M:GET URL:"/openid-connect-auth/logout" CA:10.x.x.178[10.x.x.63] F:0.000 ST:302 B:142 CTRESP:"text/html" SI:- SU:- LA:10.x.x.162 JN: S:- T:b56fb7dce5807f4b1feb3175990bb3d8
Apr  3 03:20:25 mycompany-auth-svc-proxy1-devb nginx: BR:"GET /openid-connect-auth/logoutSuccessful.html HTTP/1.1" TS:2020-04-03T03:20:25+03:00 M:GET URL:"/openid-connect-auth/logoutSuccessful.html" CA:10.x.x.178[10.x.x.63] F:0.000 ST:200 B:510 CTRESP:"text/html" SI:- SU:- LA:10.x.x.162 JN: S:- T:e3246061ca14f1b25da15652bf43a7d6
Apr  3 03:20:29 mycompany-auth-svc-proxy1-devb nginx: BR:"GET / HTTP/1.1" TS:2020-04-03T03:20:29+03:00 M:GET URL:"/" CA:10.x.x.178[10.x.x.63] F:0.000 ST:302 B:142 CTRESP:"text/html" SI:- SU:- LA:10.x.x.162 JN: S:- T:a18e7c2881d65928053d5d01d79f68e2
Apr  3 03:20:46 mycompany-auth-svc-proxy1-devb nginx: BR:"GET /openid-connect-auth/redirect_uri?state=77f388928a7d5be3284b653d8d14bc6e&session_state=d1ac9d67-1b00-4386-9b2e-f2d862700dc2&code=f5ed3d18-bfe4-40fe-bf19-05a3abe586b6.d1ac9d67-1b00-4386-9b2e-f2d862700dc2.e330def0-182f-4d93-8887-97928f014dc4 HTTP/1.1" TS:2020-04-03T03:20:46+03:00 M:GET URL:"/openid-connect-auth/redirect_uri?state=77f388928a7d5be3284b653d8d14bc6e&session_state=d1ac9d67-1b00-4386-9b2e-f2d862700dc2&code=f5ed3d18-bfe4-40fe-bf19-05a3abe586b6.d1ac9d67-1b00-4386-9b2e-f2d862700dc2.e330def0-182f-4d93-8887-97928f014dc4" CA:10.x.x.178[10.x.x.63] F:0.059 ST:302 B:142 CTRESP:"text/html" SI:- SU:- LA:10.x.x.162 JN: S:- T:305e43d6582f9e47794bb15e610042e5
Apr  3 03:20:46 mycompany-auth-svc-proxy1-devb nginx: BR:"GET / HTTP/1.1" TS:2020-04-03T03:20:46+03:00 M:GET URL:"/" CA:10.x.x.178[10.x.x.63] F:0.000 ST:200 B:12336 CTRESP:"text/html; charset=utf-8" SI:2295f5938fea1f4bdfd8fa8d910aecb9 SU:admin LA:10.x.x.162 JN: S:- T:ece0ff5632c2402a532e96fc4cae345a
Apr  3 03:20:49 mycompany-auth-svc-proxy1-devb nginx: BR:"GET /jwt/ HTTP/1.1" TS:2020-04-03T03:20:49+03:00 M:GET URL:"/jwt/" CA:10.x.x.178[10.x.x.63] F:0.000 ST:200 B:6771 CTRESP:"text/html" SI:2295f5938fea1f4bdfd8fa8d910aecb9 SU:admin LA:10.x.x.162 JN: S:- T:636548d2dfc8e30178e7024ec761c5c9
Apr  3 03:25:30 mycompany-auth-svc-proxy1-devb nginx: BR:"GET /openid-connect-auth/logout HTTP/1.1" TS:2020-04-03T03:25:30+03:00 M:GET URL:"/openid-connect-auth/logout" CA:10.x.x.178[10.x.x.63] F:0.000 ST:302 B:142 CTRESP:"text/html" SI:- SU:- LA:10.x.x.162 JN: S:- T:6af6beffc9b3e950452d31874f42b954
Apr  3 03:25:59 mycompany-auth-svc-proxy1-devb nginx: BR:"GET / HTTP/1.1" TS:2020-04-03T03:25:59+03:00 M:GET URL:"/" CA:10.x.x.178[10.x.x.63] F:0.000 ST:302 B:142 CTRESP:"text/html" SI:- SU:- LA:10.x.x.162 JN: S:- T:dc478f3d488cd2749298bcc452b66f24

Уровни логирования#

Можно настроить следующие уровни логирования: warn, debug. По умолчанию используется уровень логирования warn. Уровень логирования debug включается в профиле развертывания посредством переключения параметра debug в файле proxy. yml. Использование уровня логирования debug в штатном режиме не рекомендуется из-за больших ресурсозатрат и падения производительности.

Примечание

При установке на ПРОМ среду(тип стенда prom), средствами Platform V DevOps Tools (CDJE), возможность задания уровня логирования в debug отсутствует (отключено по соображениям безопасности).