Skip to content

3CX V20 Update 9 · Centralized security monitoring

Forward 3CX logs to your SIEM

3CX V20 Update 9 introduced Custom Remote Syslog, letting you forward system and security logs to an external syslog server or SIEM. The ECOLOR technical team connects 3CX to your monitoring platform and configures retention and alerting.

Centralized monitoring, audit trails, and alerts on failed authentications and suspected toll fraud — without replacing 3CX’s built-in security.

  • 3CX V20 Update 9
  • Forward logs to your SIEM
  • Centralized monitoring
3CX Syslog and SIEM integration

What is 3CX remote syslog / SIEM integration?

3CX remote syslog / SIEM integration is the forwarding of system and security logs from your 3CX phone system to an external syslog server or SIEM platform such as Splunk, Wazuh, Graylog, or Microsoft Sentinel. It lets you collect communications events in one place alongside the rest of your organization’s logs so they can be monitored, alerted on, and retained centrally.

3CX added the Custom Remote Syslog feature in the stable V20 Update 9 release. Instead of reviewing logs only inside the 3CX console, events are streamed to your security monitoring platform where they can be correlated with alert rules, dashboards, and incident-detection logic. For a phone system, this matters because voice infrastructure is a frequent target: exposed SIP endpoints attract brute-force login attempts, and a compromised extension can be abused to place expensive international calls. Surfacing those events in the same platform your team already watches means telephony threats are no longer a blind spot separate from the rest of your security posture.

This capability complements 3CX’s built-in security — it does not replace it. The built-in firewall, IP blacklisting, and outbound-call fraud detection continue to operate as before; log forwarding gives your security team centralized visibility across your whole environment. In practice, most organizations adopt it for one of three reasons: they already run a SOC and want telephony events feeding the same pipeline, they need to retain audit logs beyond what a single appliance conveniently stores, or they want automated alerting on high-risk events rather than manual log review after an incident has already happened.

  • Best suited to organizations running a SOC or a SIEM platform
  • Useful for teams that must retain and centrally monitor audit logs
  • Works with any standard syslog server or SIEM that accepts syslog input

What 3CX SIEM integration delivers

Remote syslog forwarding

Stream 3CX system and security logs to an external syslog server in a standard format your collector already understands.

SIEM integration

Correlate telephony events with the rest of your estate in your SIEM — Splunk, Wazuh, Graylog, or Microsoft Sentinel.

Centralized monitoring

Bring 3CX events together with the rest of your organization’s logs in one dashboard so voice is no longer a blind spot.

Audit trail

Retain a searchable record of admin actions and system events for auditing, review, and after-the-fact investigation.

Fraud / anomaly alerts

Alert rules on failed authentications and unusual outbound-call patterns so your team is notified early, not after the bill.

Retention & compliance logging

Set a log retention policy that supports your organization’s audit and compliance program requirements.

What you can monitor

Event typeWhy it mattersWhere it goes
Failed authenticationsDetect brute-force and credential-stuffingSIEM alert
Unusual outbound patternsToll-fraud signalSIEM alert
Admin actions & config changesAudit trail for accountabilitySyslog store
System & service eventsTrack health and outagesSyslog store
Security & blacklist eventsMonitor suspicious activityAlert & dashboard

Available events depend on what 3CX exposes in V20 Update 9 and what your syslog / SIEM accepts.

How ECOLOR connects 3CX to your SIEM

  1. Define events & retention

    We agree which 3CX events matter to your organization, how long to keep them, and who watches the alerts — scoping the pipeline to what you’ll actually act on rather than forwarding noise.

  2. Configure Custom Remote Syslog

    We enable and configure remote syslog forwarding inside 3CX V20 Update 9 toward your monitoring destination, setting the collector address and confirming the system is emitting the expected events.

  3. Connect the SIEM

    We wire the syslog output into your SIEM (Splunk / Wazuh / Graylog / Sentinel), verify parsing, and confirm events are arriving with the fields your rules depend on.

  4. Build alert rules

    We build detection rules for failed authentications, suspected fraud patterns, admin changes, and other critical events, mapped to how your team wants to be notified.

  5. Validate & tune

    We test the flow with representative events and tune rules to reduce false positives while ensuring genuinely critical events are always captured and alerted.

Log flow

3CX system & security logsCustom Remote SyslogYour syslog / SIEM (Splunk/Wazuh/Sentinel)Dashboards & alerts

What you need

  • 3CX V20 Update 9 or later
  • A syslog server or SIEM that accepts syslog input
  • A defined log retention policy
  • Secure network connectivity between 3CX and the monitoring destination
  • A team or service that watches and acts on alerts

If you don’t have a SIEM yet, the ECOLOR team can help you choose a suitable destination within our cybersecurity services scope.

Saudi deployment notes & limits

Log forwarding complements 3CX’s built-in security and does not replace it. Core protection — the built-in firewall, IP blacklisting, and fraud detection — keeps running inside 3CX, while syslog / SIEM adds a layer of centralized visibility and monitoring. Treat the two as layers of the same strategy rather than alternatives: 3CX defends the system at the edge, and the SIEM gives you the record, correlation, and alerting on top of it.

This integration supports the audit trails your compliance program may require, but it is not legal advice and does not by itself guarantee compliance with any regulation. How far it contributes to compliance depends on your organization’s overall program and the requirements of the relevant regulators. If your logging is driven by a specific Saudi framework — for example expectations set by the National Cybersecurity Authority or data-handling obligations under the Personal Data Protection Law — confirm the exact retention, integrity, and access requirements with your own compliance and legal advisers before relying on any technical configuration.

Plan for log retention duration, storage capacity, and who monitors and responds to alerts. Logs no one watches provide no real protection; the value comes from well-defined alert rules and a structured response process. Consider time-zone and clock synchronization so events line up with the rest of your estate, the network path and bandwidth between 3CX and the collector, and whether the syslog transport should be secured in transit. During implementation, ECOLOR typically validates that events actually reach the collector, that the fields you care about are parsed correctly, and that a test failed-login or anomaly triggers the alert you expect — before treating the pipeline as production-ready.

Frequently asked questions

Which 3CX version supports remote syslog?
3CX added Custom Remote Syslog in the stable V20 Update 9 release. You need V20 Update 9 or later to forward logs to an external destination.
Which SIEMs work?
Any standard syslog server or SIEM that accepts syslog input — including Splunk, Wazuh, Graylog, and Microsoft Sentinel. The ECOLOR team handles the connection and verifies events arrive.
Can it alert on toll fraud?
Yes. By building rules in your SIEM that detect unusual outbound-call patterns and failed authentications, your team can receive an immediate alert on suspected toll fraud.
Does this make us compliant with PDPL / NCA?
Log forwarding supports audit logging and centralized monitoring, but compliance depends on your organization’s overall program and the relevant regulators’ requirements. This is not legal advice, and the integration does not by itself guarantee compliance.
Does it replace 3CX built-in security?
No. Log forwarding complements 3CX’s built-in security and does not replace it; the built-in firewall, blacklisting, and fraud detection continue to operate as before.
What events can be forwarded?
System and security logs such as failed authentications, admin actions, service events, and suspicious-activity patterns — as exposed by 3CX in V20 Update 9.

Centralize 3CX monitoring with ECOLOR

The ECOLOR technical team helps you forward 3CX logs to your SIEM and build the right alert rules for failed authentications and suspected toll fraud. Contact us to discuss your environment at [email protected].

ECOLOR Technologies — ECOLOR Technologies — Riyadh, Saudi Arabia

3CX Solution Provider · Fanvil Platinum Partner | Yealink Gold Partner

Unified number: 920033987 · WhatsApp: +966920033987 · [email protected]

Log forwarding complements 3CX’s built-in security and does not by itself guarantee regulatory compliance — compliance depends on your overall program.