Logback’s SiftingAppender can route each logging event to a file selected by a runtime value. To separate work handled by different threads, put an application-controlled identifier in the thread’s MDC and use the default MDCBasedDiscriminator to select a nested file appender. For request and job logs, use the request or job ID rather than the worker thread’s name: application servers commonly reuse threads.
How SiftingAppender chooses a log file
A SiftingAppender evaluates a discriminator for each event, then sends that event to a child appender associated with the discriminator’s value. It creates child appenders from the configuration inside <sift>, so a new value can produce a new file. Logback’s manual describes this pattern for separating events such as different user sessions: Logback SiftingAppender documentation.
With the default MDC-based discriminator, the key you configure is read from the event’s MDC. The value is available as a variable inside the sift template, where you can use it in both the child appender’s name and its filename. If the key is missing, Logback uses the configured default value. The official example routes userid=Alice to Alice.log and also produces unknown.log for events without a user ID: Logback SiftingAppender example.
Configure an MDC-based file per identifier
This example uses the MDC key threadLog. The name is only a label: for request processing, set it to a request ID; for background work, use a job ID. The nested FileAppender writes to logs/<identifier>.log.
#1 Best Overall
- Dell PowerEdge R730xd 24B SFF 2U Server
- 2x Intel Xeon E5-2690 v4 2.6Ghz 14-Core (28-cores Total)
- 128GB DDR4 RAM – 4x 1.2TB 10K SAS 2.5” 12Gb/s
- Dell H730P mini 2GB 12Gb/s RAID
- 2x 750W PSU - 2x 10Gb SFP+ 2x 1Gb (RJ45) NIC
<configuration>
<appender name="SIFT" class="ch.qos.logback.classic.sift.SiftingAppender">
<discriminator>
<key>threadLog</key>
<defaultValue>unknown</defaultValue>
</discriminator>
<sift>
<appender name="FILE-${threadLog}" class="ch.qos.logback.core.FileAppender">
<file>logs/${threadLog}.log</file>
<append>true</append>
<encoder>
<pattern>%d [%thread] %-5level %logger{36} - %msg%n</pattern>
</encoder>
</appender>
</sift>
</appender>
<root level="INFO">
<appender-ref ref="SIFT"/>
</root>
</configuration>
Set and clear the MDC value around the work
Set the value before the first log call that should use it, then remove it when the work finishes. Use a value your application controls and has made safe for filenames; do not put unsanitized user input into a path.
MDC.put("threadLog", safeId);
try {
logger.info("work started");
doWork();
} finally {
MDC.remove("threadLog");
}
Choose an identifier that matches the work
Request or job ID
An application-controlled request or job ID identifies the unit of work, even when different workers handle different tasks over time. Logback’s MDC manual describes MDC as per-thread context, with operations affecting the current thread and its children: Logback MDC documentation.
Rank #2
- Model: Dell OptiPlex 7050 Small Form Factor (SFF)
- Processor: Intel Core i7-7700 3.60 GHz
- Memory: 32GB DDR4 Ram
- Storage: 1TB Solid State Drive (SSD) Fast Boot + Storage
- Operating System: Windows 11 Pro (64-bit)
Thread name
Thread names can help identify the executing worker, but they are not a reliable request boundary in server systems that recycle threads. A reused worker can process many unrelated requests, so using its name as the discriminator can group unrelated activity in one file. The Logback manual cautions about interpreting thread names in server environments: Logback MDC documentation.
Handle pooled and asynchronous work safely
MDC is thread-associated, so do not assume a value set on one thread will automatically be present in every executor task or asynchronous callback. Make sure the intended value is available on the thread that performs the logging, and remove or restore it when the task ends. Otherwise, a pooled worker may retain a previous task’s routing value and send later events to the wrong file.
Recommended Free Tools
Rank #3
- 2.80 GHz processor speed ensures efficient operation with consistent reliability
- Intel Xeon 2.80 GHz processor provides enterprise-grade performance with built-in security and remote management capabilities
- Quad-core (4 Core) processor core helps server process data quickly and reliably for maximum productivity
- 1 processors supported for faster processing and improved access to data, optimizing performance under heavy loads
- With 16 GB memory, you can multitask between applications seamlessly, keeping productivity high and response times quick
For asynchronous logging, Logback documents that inexpensive event data, including thread name and MDC, is copied by default when the logging event is created. Set MDC before the logging call; changing it later does not change the already-created event’s context. See Logback asynchronous appender documentation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Plan for file and appender growth
Each distinct discriminator value may create a child appender and a corresponding file. Logback retires and removes a child appender after it has not been accessed for the configured timeout; the documented default stale timeout is 30 minutes. The documented default maxAppenderCount is Integer.MAX_VALUE, so do not assume the default meaningfully caps growth. See Logback SiftingAppender lifecycle and configuration.
Rank #4
- MODEL P74439-005: Compact and affordable HPE ProLiant MicroServer Gen11 powered by Intel Pentium Gold G7400 3.7GHz processor, ideal for file sharing, NAS, and basic business workloads
- READY OUT OF THE BOX: Includes 16GB DDR5 UDIMM memory (expandable to 128GB), one 1TB SATA 6G Business Critical HDD, embedded Intel VROC SATA, dedicated iLO-M.2 port kit, 180w external power adapter and 1/1/1 warranty for dependable plug-and-play server operation
- WHISPER-QUIET & SPACE-SAVING: Ultra-compact mini tower design fits easily in small office spaces; supports wall, flat, or vertical placement for deployment flexibility
- INTEGRATED REMOTE MANAGEMENT: Comes with HPE iLO 6 and embedded TPM 2.0 for secure, license-free remote server administration through shared port access
- EXPANDABLE DESIGN: Two PCIe slots (including PCIe 5.0) and four LFF-NHP drive bays provide robust options for storage and component scalability. Features new MR408i-p controller support for enhanced storage performance
- Use identifiers with an intentional scope and lifecycle, not an unbounded stream of arbitrary values.
- Choose a stale-appender timeout and maximum count that fit the number of simultaneously active IDs and the application’s file-handling needs.
- Consider whether a centralized log store with searchable request or job IDs is more manageable than maintaining a separate file for every ID.
The documented timeout and count are defaults, not performance guarantees. The right limits depend on the number of active identifiers and how long their appenders remain in use.
Quick Recap
Best Value
- HP Z4 G4 Workstation Tower
- Intel Xeon W-2133 6-Core 3.6GHz (3.9GHz Turbo)
- 64GB DDR4 Memory - Nvidia Quadro P400 2GB
- 512GB NVMe M.2 SSD (boot) + 2TB HDD (storage)
- Windows 11 Pro 64-bit
Check the routing when events land in the wrong file
- Events go to
unknown.log: confirm the configured MDC key exactly matches the key set in code, and that it is populated before logging. - Unrelated requests share a file: check whether the discriminator uses a recycled thread name or an identifier broader than one request or job.
- A task inherits the prior task’s file: ensure task cleanup removes or restores the MDC value on pooled threads.
- Files or active appenders accumulate: review identifier cardinality, timeout, and
maxAppenderCount; a distinct value can create a distinct child appender. - Identifiers create unsafe paths: replace external or unsanitized input with a validated, application-controlled filename-safe value.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →

