Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Corporate Server Logs & Certificate Diagnostics

For Administrators: Logging Levels
CTS
ETS
eCTS

The following logging levels are available for server services:

Level Description
error Outputs only errors. Recommended for systems with over 10K users.
warning Optimal for continuous operation.
info The default level for basic diagnostics.
debug Maximum detail. Do not use continuously: may cause system hangs.

How to Set the Logging Level

Example for the Active Directory integration service (setting the debug level):

Architecture Command
Docker docker exec -it cts-ad_integration-1 bin/ad_integration rpc "Logger.configure(level: :debug)" Where cts-ad_integration-1 is the container name, and ad_integration is the binary file name.
Kubernetes kubectl exec -it {ad-integration} -- bin/ad_integration rpc "Logger.configure(level: :debug)" Where {ad-integration} is the pod name or ID.

Expected response: ok.


The logging level can only be set for Elixir services (ad_int, messaging, trusts, etc.). Services like nginx, Kafka, and similar do not support this feature.

Permanent Logging Level Change

Architecture Commands/Steps
Docker

For a specific container (e.g., trusts), add the following to the /opt/express/settings.yaml file:

trusts_env_override: LOGGER_LEVEL: debug

Where trusts_env_override is a unique directive (must be the only one in the file). After changes, rebuild the containers:

dpl -d trusts

To change the logging level for all containers, add the following to settings.yaml:

logger_level: debug
Kubernetes Modification is not recommended.
For continuous operation, use the warning level, not debug.
For Administrators: Corporate Server Docker Container Logs
CTS
ETS
eCTS

To collect logs via the admin panel:

  1. Go to the Containers section.
  2. Click >_logs next to the desired container.
  3. Specify the date and number of lines, uncheck follow (to avoid real-time messages), and click show.

When the buffer overflows, old logs are overwritten. Logs are cleared when the container is updated.

Collecting Logs via Console

The tail key outputs the last lines:

cd /opt/express && DPL_PULL_POLICY=never dpl --dc logs --tail=1000 ad_integration > logs.txt

Examples for other services:

cd /opt/express && DPL_PULL_POLICY=never dpl --dc logs --tail=1000 messaging > logs.txt cd /opt/express-voice && DPL_PULL_POLICY=never dpl --dc logs --tail=1000 coturn > logs.txt

The since and until keys output logs for a period:

cd /opt/express && DPL_PULL_POLICY=never dpl --dc logs --since=1h messaging cd /opt/express && DPL_PULL_POLICY=never dpl --dc logs --since=2025-01-27T07:10:00Z --until=2025-01-28T07:50:00Z messaging

For more details: Docker documentation.

For Administrators: Container Logs in Kubernetes Pods
CTS
ETS
eCTS

Basic information: Kubernetes. For more details: kubectl logs.

  1. Get the list of pods: kubectl get pods -n <namespace>

    If there are multiple pods with the target container, the following commands must be executed for each of them.

  2. Enable INFO mode for the container inside the pod: kubectl -n <namespace> exec -ti <pod_id> -- bin/<service_name> rpc "Logger.configure(level: :info)"
  3. Reproduce the issue.
  4. Collect logs: kubectl logs --tail=2000 -n <namespace> <pod_id> > pod_id.log
  5. Revert to the previous logging level, e.g. ERROR: kubectl -n <namespace> exec -ti <pod_id> -- bin/<service_name> rpc "Logger.configure(level: :error)"
  6. Submit the logs to eXpress technical support.
For Administrators: SSL Certificates Diagnostics
CTS
ETS
eCTS
⚠️ Some tools may be unavailable from the corporate network.

Verification methods:

Method Steps
Via Browser Open https://server_FQDN/system/settings/version and check the certificate details.
Yandex Browser, Chromium GOST, and “Atom” have Russian CA certificates built in, including those of the Ministry of Digital Development, so they cannot be used to check whether the certificates are installed in the system. In addition, if Kaspersky antivirus or other security software is installed on the PC, their certificate may be displayed instead of the server certificate.
Using Online Tools
  • SSL Server Test
    • In the Hostname field, enter the server address.
    • To view the server’s root certificate authority, hover over the Issuer field and check the O= value for the issuing organization.
    • On this page, the certificate is evaluated against multiple criteria.
      ⚠️ If the certificate is rated below A+, mobile devices may experience issues connecting to the corporate server.
  • SSL Checker
    • In the Server Hostname field, enter the server address and press Enter.
    These resources cannot be used to analyze certificates from Russian certification authorities or certificates of servers to which access is blocked for foreign IP addresses.
Using CURL In the command line or terminal, enter curl -vI https://server_address and press Enter.