Dynamic Modules Access Logger

The Dynamic Modules Access Logger allows you to write access loggers in a dynamic module. This can be used to implement custom logging behavior, such as:

  • Sending logs to custom backends.

  • Custom log formatting and aggregation.

  • Real-time metrics extraction from access logs.

  • Integration with proprietary logging systems.

The logger receives completed request information including:

  • Request and response headers (and trailers).

  • Response code and details.

  • Response flags (indicating errors, timeouts, etc.).

  • Timing information (request duration, upstream latency, etc.).

  • Byte counts (request/response sizes and upstream/downstream wire bytes).

  • Upstream information (cluster, host, connection details).

  • TLS information (versions, certificates).

  • Tracing information (trace ID, span ID).

  • Dynamic metadata and filter state.

Downstream wire byte counts are available through the Rust SDK’s LogContext::downstream_wire_bytes(). They use the same stream counters as DOWNSTREAM_WIRE_BYTES_RECEIVED and DOWNSTREAM_WIRE_BYTES_SENT and can be nonzero for locally generated responses that never reach an upstream. For HTTP streams, these counters include protocol overhead accounted for by the codec, rather than only body bytes. Both values are zero when the downstream bytes meter is unavailable. The existing LogContext::bytes_info() wire byte fields continue to report upstream traffic.

Example Configuration

access_log:
- name: envoy.access_loggers.dynamic_modules
  typed_config:
    "@type": type.googleapis.com/envoy.extensions.access_loggers.dynamic_modules.v3.DynamicModuleAccessLog
    dynamic_module_config:
      name: my_logger
    logger_name: json_logger
    logger_config:
      "@type": type.googleapis.com/google.protobuf.Struct
      value:
        output_path: "/var/log/envoy/access.json"
        buffer_size: 100

For more details on dynamic modules, see the architecture overview.