Skip to main content
There is now one setting for this. smsg.diagnostics supplies the default for message.trace.mode and smsg.cdr.events, and the control panel sets it at Configuration → Gateway → Diagnostics. See Diagnostics. The individual keys below still work and still win when set on their own.

The five logs

auth-failed.log follows different rules from the other four

It is the file fail2ban reads to decide what to block, so it is deliberately not like its neighbours.
Turning it off turns off the evidence, not the enforcement. Existing bans stand, and nothing new is ever recorded — so an attack in progress becomes invisible rather than harmless.

Bounds — and the one that has none

conf.example/fireflo.env ships 5, so an install made from it keeps five and a hand-built one keeps one. Neither is wrong; they are just different, and it is worth knowing which you have.
httpapi.log is covered by neither. Quarkus rotates it daily and offers no retention to go with that — there is no setting for it — so it writes one file per day and keeps every one of them forever. Nothing in the gateway will ever remove them.fireflo-install handles this with a daily systemd timer that deletes rotated files older than --log-retain-days, never touching the five live ones. Installing by hand means arranging that yourself, or accepting unbounded growth.

What the access log deliberately omits

httpapi.log records method, path, protocol, status, bytes sent, response time, referer and user agent. It intentionally omits the query string. Credentials travel in an Authorization header rather than the URL, but GET /secure/rate still takes to and content as query parameters, and dlr_url and callback_url are client-supplied and routinely carry tokens of their own.
Do not add %U, %r, %q, or %{i,Authorization} to quarkus.http.access-log.pattern. If you customise it, avoid %r, %q, %{QUERY_STRING} and %{q,...} unless the resulting logs are treated as sensitive data.

Diagnostic flags that write secrets

Worker flags log.pdus, log.bytes, print.msgs, print.resps and print.mos are disabled by default. Enabling any of them can write SMPP credentials, phone numbers, provider identifiers, callback URLs and message bodies to logs.
For diagnosing one session, prefer capture over log.pdus: a capture is bounded, held in memory, scoped to a single session, and expires on its own, where log.pdus writes every session’s PDUs to a shared file until someone remembers to turn it off.

Message lifecycle tracing

message.* lifecycle logs are controlled by message.trace.mode:

Docker log variables