
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
log4-microservice
Advanced tools
A full packaged logger that supports structured logging with multiple adapters like pino, winston, bunyan. It has support for MDC (mapped domain context) and correlationIds.
LoggerSDK for Microservices with multiple adapters eg: Pino, Winston, Bunyan.
npm install log4-microservice --save
process.env.SERVICE = 'Payment'; // Name of the microservice
process.env.LOG_ADAPTER = 'pino'; // any one of the pino, winston, bunyan values
process.env.LOG_LEVEL = 'debug';
process.env.LOG_PATH = 'logs'; // log directory path
process.env.LOG_FILE = 'payment.log'; // log file name
// Entry Point of your Microservice
// server.js
const { Log4Microservice } = require('log4-microservice');
// Typescript
// import { Log4Microservice } from 'log4-microservice'
//...other initialization code
function configureLogger() {
const logOptions = {
level: process.env.LOG_LEVEL,
logPath: process.env.LOG_PATH,
logFile: process.env.LOG_FILE,
};
Log4Microservice.setLoggerOptions(logOptions);
Log4Microservice.addAdapter(process.env.LOG_ADAPTER, Log4Microservice.setAdapter(process.env.LOG_ADAPTER));
}
// should be configured once hence in entry point file
configureLogger();
// mymodule.js
const { Log4Microservice } = require('log4-microservice');
const logger = new Log4Microservice('mymodule');
logger.debug('debug');
logger.info('info');
logger.error(new Error());
logger.log('level', msg, arbitarydata, correlationIdJson)
NOTE: scope will be truncated to first 6 chars for formatting.
In order to add the correlationIds often known as MDC (Mapped Domain Context or Context Mapping) related to specific event it can be supplied to any of the loggers API as the last argument. CorrelationId should be a valid JSON Object. Incase if correlationIds are not passed on default correlationIds assigned during instantiation will be used.
Often when there are lot of microservices and logs are been forwarded it becomes difficult to find the reason for error and sequence of events that might have caused the error. MDC approach helps to group together the events that are related to specific event for eg. Order Checkout failed or Payment Failure on Ecommerce site.As customer is unaware of the internal things it is wise idea to add some related information as correlationIds like { orderID: 101 } so it can be searched quickly.
processPayment(orderData) {
logger.debug(`Processing payment for orderID ${orderData.id}`, { orderId: orderData.id });
}
node examples server.js
<source>
@type tail
path /tmp/logs/payment.log
tag payment.stdout
pos_file /tmp/payment.log.pos
<parse>
@type json
</parse>
</source>
<match payment.stdout>
@type http
log_level debug
endpoint https://log-api.eu.newrelic.com/log/v1
http_method post
content_type application/json
headers {"x-license-key":"ENTER_LICENSE_KEY" }
<format>
@type json
</format>
<buffer>
flush_interval 2s
</buffer>
</match>
HappyCoding :bowtie:
FAQs
A full packaged logger that supports structured logging with multiple adapters like pino, winston, bunyan. It has support for MDC (mapped domain context) and correlationIds.
We found that log4-microservice demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.