Logging

IdentitySuite includes a built-in logging system based on Serilog — configured, managed, and accessible directly from the admin interface

Overview

IdentitySuite manages logging internally via Serilog, independently of the host application. Log entries are written to rolling files stored in the IdentitySuite/logs/ folder within the application's content root, and are accessible directly from the Dashboard without needing to access the server filesystem.

Serilog as the single logging provider

When IdentitySuite is installed, Serilog replaces the default ASP.NET Core logging provider via UseSerilog(). Any ILogger<T> injected anywhere in the application — including the host — will automatically write through Serilog. No additional configuration is required.

💡

Development vs Production

In development environments, log entries are also written to the console with ANSI color formatting for easy reading. In production, only the file sink is active to avoid unnecessary console output.

Configuration

Logging behavior is controlled by the Logging section of the IdentitySuite settings file. All properties have sensible defaults and can be adjusted without modifying application code.

Property Default Description
MinimumLevel Warning The global minimum log level. Entries below this level are discarded. Valid values: Verbose, Debug, Information, Warning, Error, Fatal. Can also be changed at runtime from the Dashboard without restarting the application.
FileSizeLimitBytes 9437184 Maximum size in bytes for a single log file before a new file is created for the same day. The default is 9 MB. When this limit is reached, Serilog appends a numeric suffix to the filename (e.g. identitysuite-20260509_001.txt).
RetainedFileCountLimit 10 Maximum number of log files to retain. When the limit is reached, the oldest files are automatically deleted. This applies across all files including size-split files for the same day.
RollingInterval Day Frequency at which a new log file is created. Valid values: Infinite, Year, Month, Day, Hour, Minute. The default Day creates one file per day named identitysuite-YYYYMMDD.txt.
LevelOverrides See below Per-namespace minimum level overrides. Allows suppressing or amplifying log output from specific namespaces independently of the global minimum level.

LevelOverrides

LevelOverrides is a dictionary that maps namespace prefixes to a minimum log level. Any logger whose category starts with the specified prefix will use the override level instead of the global minimum. This is particularly useful for suppressing verbose output from infrastructure namespaces like Microsoft or OpenIddict while keeping a lower global level for application code.

The following overrides are configured by default for production enviroment:

Namespace Level
Microsoft Warning
System Warning
Microsoft.Hosting.Lifetime Information
Quartz Warning
OpenIddict.Server.OpenIddictServerDispatcher Warning
OpenIddict.Core.OpenIddictTokenManager Warning
OpenIddict.Server.AspNetCore.OpenIddictServerAspNetCoreHandler Warning
💡

Override precedence

Overrides are matched by prefix — a more specific namespace takes precedence over a broader one. For example, Microsoft.Hosting.Lifetime set to Information takes precedence over Microsoft set to Warning, so lifetime events remain visible even when all other Microsoft logs are suppressed.

Runtime Level Change

The global minimum log level can be changed at runtime from the Dashboard without restarting the application. The change takes effect immediately and is persisted to the settings file so it survives restarts.

Typical use case

When investigating a production issue, temporarily lower the level to Information or Debug to capture detailed diagnostic output. Once the issue is resolved, raise the level back to Warning to reduce noise and file size. No redeployment or server access is required.

Impact of low log levels in production

Setting the level to Debug or Verbose in a busy production environment generates a very high volume of log entries. This can significantly increase disk usage and cause log files to roll over more frequently, consuming the retained file slots faster. Remember to raise the level back to Warning once diagnostics are complete.

Log Files

Log files are stored in IdentitySuite/logs/ within the application content root. Files are named using the pattern identitysuite-YYYYMMDD.txt. When the file size limit is reached within the same day, Serilog creates additional files with a numeric suffix: identitysuite-YYYYMMDD_001.txt, identitysuite-YYYYMMDD_002.txt, and so on.

Log entry format

Each log entry follows this fixed format:

2026-05-09 23:44:45 [INF] OpenIddict.Server.OpenIddictServerDispatcher
The authorization request was successfully extracted.

2026-05-09 23:44:46 [ERR] IdentitySuite.Application.Identity.Manage.Pages.Dashboard
Error processing request for client blazor-client
System.InvalidOperationException: Something went wrong during token validation
   at IdentitySuite.Application.Identity.Manage.Pages.Dashboard.LoadAsync()

Each entry consists of up to three parts: the header line with timestamp, level, and source context; the message (which may span multiple lines for structured output such as JSON); and optionally the exception with its full stack trace.