# Plex Media Server Logs FORMAT

**URL:** https://forums.plex.tv/t/plex-media-server-logs-format/904583
**Category:** Plex Media Server
**Tags:** other-dev
**Created:** [February 4, 2025, 6:25pm UTC](https://forums.plex.tv/t/plex-media-server-logs-format/904583 "2025-02-04T18:25:09Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![misteralexander](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@misteralexander](https://forums.plex.tv/u/misteralexander)
#### Post date: [February 4, 2025, 6:25pm UTC](https://forums.plex.tv/t/plex-media-server-logs-format/904583/1 "2025-02-04T18:25:09Z")

</div>

Hello -

I just installed SPLUNK (docker) and I would like to forward all the Plex logs to there.

During the setup, I am asked to select a SOURCE TYPE … what format are the log in, so Splunk knows how to intelligently format them.

My options are: [(table source)](https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Listofpretrainedsourcetypes#Pretrained_source_types)

| Category | Source Types |
| --- | --- |
| **Application servers** | log4j, log4php, weblogic\_stdout, websphere\_activity, websphere\_core, websphere\_trlog, catalina, ruby\_on\_rails |
| **Databases** | db2\_diag, mysqld, mysqld\_error, mysqld\_bin, mysql\_slow |
| **E-mail** | exim\_main, exim\_reject, postfix\_syslog, sendmail\_syslog, procmail |
| **Operating systems** | linux\_messages\_syslog, linux\_secure, linux\_audit, linux\_bootlog, anaconda, anaconda\_syslog, osx\_asl, osx\_crashreporter, osx\_crash\_log, osx\_install, osx\_secure, osx\_daily, osx\_weekly, osx\_monthly, osx\_window\_server, windows\_snare\_syslog, dmesg, ftp, ssl\_error, syslog, sar, rpmpkgs |
| **Metrics** | collectd\_http, metrics\_csv, statsd |
| **Network** | novell\_groupwise, tcp |
| **Printers** | cups\_access, cups\_error, spooler |
| **Routers and firewalls** | cisco\_cdr, cisco:asa, cisco\_syslog, clavister |
| **VoIP** | asterisk\_cdr, asterisk\_event, asterisk\_messages, asterisk\_queue |
| **Web servers** | access\_combined, access\_combined\_wcookie, access\_common, apache\_error, iis\* |
| **Splunk software** | splunk\_com\_php\_error, splunkd, splunkd\_crash\_log, splunkd\_misc, splunkd\_stderr, splunk-blocksignature, splunk\_directory\_monitor, splunk\_directory\_monitor\_misc, splunk\_search\_history, splunkd\_remote\_searches, splunkd\_access, splunkd\_ui\_access, splunk\_web\_access, splunk\_web\_service, splunkd\_conf\*, django\_access, splunk\_help, mongod |
| **Non-log files** | csv\*, psv\*, tsv\*, \_json\*, json\_no\_timestamp, fs\_notification, exchange\*, generic\_single\_line |
| **Miscellaneous** | snort, splunk\_disk\_objects\*, splunk\_resource\_usage\*, kvstore\* |

I appreciate the help, as I could not find any documentation about the logging format.

---

<div class="post-metadata">

### Author: ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)
#### Post date: [February 5, 2025, 5:22am UTC](https://forums.plex.tv/t/plex-media-server-logs-format/904583/2 "2025-02-05T05:22:56Z")

</div>

If you put your Plex logs into any format other than the ZIP file which PMS generates, we will not be able to help you should you have difficulties.

Our tools are geared for handling that ZIP file as generated by PMS.

You will not find any information about the logfile format.  
Most of that information requires internal knowledge of how PMS works.

---

<div class="post-metadata">

### Author: ![misteralexander](https://avatars.discourse-cdn.com/v4/letter/m/a8b319/32.png) [@misteralexander](https://forums.plex.tv/u/misteralexander)
#### Post date: [February 5, 2025, 8:26pm UTC](https://forums.plex.tv/t/plex-media-server-logs-format/904583/3 "2025-02-05T20:26:46Z")

</div>

> [@ChuckPa](#):
>
> If you put your Plex logs into any format other than the ZIP file which PMS generates.

Correct, splunk is for my own dashboard and internal metrics.

> [@ChuckPa](#):
>
> You will not find any information about the logfile format.  
> Most of that information requires internal knowledge of how PMS works.

Oh, well that sucks. I think its silly to both not publicize it and to not follow a well documented standard, but that’s just me screaming in a barrel nobody cares about.

￣＼＿（ツ）＿／￣

---

<div class="post-metadata">

### Author: ![ChuckPa](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/chuckpa/32/79710_2.png) [@ChuckPa](https://forums.plex.tv/u/ChuckPa)
#### Post date: [February 5, 2025, 8:43pm UTC](https://forums.plex.tv/t/plex-media-server-logs-format/904583/4 "2025-02-05T20:43:56Z")

</div>

I understand your point very well.

There is the other side of that argument as well .

PMS, internally, changes with each update.  
Log content changes to reflect this.

Without the NDA knowledge of the internals, what you’re seeing is largely mysterious to you.

Additionally, it would be a logistics nightmare to update documentation on Logfiles with every update and maintain that across all the supported platforms and versions.

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)
#### Post date: [May 6, 2025, 8:44pm UTC](https://forums.plex.tv/t/plex-media-server-logs-format/904583/5 "2025-05-06T20:44:54Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
