Forward your 3CX operational, security and audit events directly to any Syslog server.

For large enterprises, regulated industries and any organization running a Security Operations Center (SOC), having phone system events siloed on the PBX itself is no longer enough:

  • Compliance frameworks demand centralized logging
  • Auditors demand traceability
  • SOC teams demand real-time visibility

That's why 3CX now ships with the Remote Syslog logging feature - a built-in capability that securely forwards your PBX's key events to an external Syslog server platform of your choice.

If you are a system administrator, an MSP, or an IT security lead responsible for a 3CX deployment and you are working towards ISO 27001, SOC 2, PCI DSS, or HIPAA compliance, then this feature was built for you. Read on to learn everything you need to know.

Why Remote Syslog Logging Matters

Why Remote Syslog Logging Matters

3CX stores all operational, audit and system events in its internal database. For smaller deployments, that's perfectly fine. But for enterprises bound by stricter regulatory requirements or internal policies, logs need to live somewhere centralized, tamper-evident and continuously monitored.

Remote Syslog Logging in 3CX was designed with four primary goals in mind:

  1. Enterprise-grade, standards-compliant remote logging that plugs into your existing tooling.
  2. Centralized security monitoring through SIEM/SOC systems such as Splunk, Graylog, QRadar, Wazuh, Elastic, or any RFC-compliant Syslog collector.
  3. Reduced PBX exposure by removing sensitive logs from local storage and shipping them off-box.
  4. Audit readiness, forensic investigation and operational visibility for compliance teams.

In short: your phone system finally talks to your security stack - natively, reliably and via an industry-standard protocol.

What Gets Logged

When you enable Remote Syslog, you choose exactly which event categories to forward:

  • System Alerts: health, performance and system-state notifications from the PBX itself.
  • 3CX Alerts: security-relevant events such as failed authentication attempts, blocked IPs and policy violations.
  • Audit Logs: administrative actions taken in the 3CX Admin Console, ideal for change tracking and accountability.

Each category can be toggled independently, so you only transfer what you actually need to.

Get the Most Out of Your 3CX Deployment

Custom Remote Syslog Logging is a small toggle that delivers an outsized impact: it brings your 3CX PBX into the same observability and compliance fabric as the rest of your enterprise stack.

  • For partners managing customer deployments, it's a powerful answer to the "How do we handle PBX logging?" question that comes up in every enterprise procurement conversation.
  • For internal IT and security teams, it's one more system that now lives inside your Security Information and Event Management (SIEM).

Roll it out, point it at your collector and let your auditors and your SOC team do the rest.

Join the Discussion

Join the 3CX discussion in our dedicated Partner or Customer Forums. Follow us on X and LinkedIn to stay-up-to date on latest news and feature releases.