Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Logback’s SiftingAppender can route each logging event to a file selected by a runtime value. To separate work handled by different threads, put an application-controlled identifier in the thread’s MDC and use the default MDCBasedDiscriminator to select a nested file appender. For request and job logs, use the request or job ID rather than the worker thread’s name: application servers commonly reuse threads.

How SiftingAppender chooses a log file

A SiftingAppender evaluates a discriminator for each event, then sends that event to a child appender associated with the discriminator’s value. It creates child appenders from the configuration inside <sift>, so a new value can produce a new file. Logback’s manual describes this pattern for separating events such as different user sessions: Logback SiftingAppender documentation.

With the default MDC-based discriminator, the key you configure is read from the event’s MDC. The value is available as a variable inside the sift template, where you can use it in both the child appender’s name and its filename. If the key is missing, Logback uses the configured default value. The official example routes userid=Alice to Alice.log and also produces unknown.log for events without a user ID: Logback SiftingAppender example.

Configure an MDC-based file per identifier

This example uses the MDC key threadLog. The name is only a label: for request processing, set it to a request ID; for background work, use a job ID. The nested FileAppender writes to logs/<identifier>.log.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Dell PowerEdge R730xd Server 24B SFF 2U, 2X Intel Xeon E5-2690 v4 2.6Ghz (28-cores Total), 128GB DDR4 RAM, 4X 1.2TB 10K SAS 2.5” 12Gb/s HDD, H730P 2GB RAID, NIC 10Gb + I350 1Gb (Renewed)
  • Dell PowerEdge R730xd 24B SFF 2U Server
  • 2x Intel Xeon E5-2690 v4 2.6Ghz 14-Core (28-cores Total)
  • 128GB DDR4 RAM – 4x 1.2TB 10K SAS 2.5” 12Gb/s
  • Dell H730P mini 2GB 12Gb/s RAID
  • 2x 750W PSU - 2x 10Gb SFP+ 2x 1Gb (RJ45) NIC
<configuration>
  <appender name="SIFT" class="ch.qos.logback.classic.sift.SiftingAppender">
    <discriminator>
      <key>threadLog</key>
      <defaultValue>unknown</defaultValue>
    </discriminator>
    <sift>
      <appender name="FILE-${threadLog}" class="ch.qos.logback.core.FileAppender">
        <file>logs/${threadLog}.log</file>
        <append>true</append>
        <encoder>
          <pattern>%d [%thread] %-5level %logger{36} - %msg%n</pattern>
        </encoder>
      </appender>
    </sift>
  </appender>

  <root level="INFO">
    <appender-ref ref="SIFT"/>
  </root>
</configuration>

Set and clear the MDC value around the work

Set the value before the first log call that should use it, then remove it when the work finishes. Use a value your application controls and has made safe for filenames; do not put unsanitized user input into a path.

MDC.put("threadLog", safeId);
try {
    logger.info("work started");
    doWork();
} finally {
    MDC.remove("threadLog");
}

Choose an identifier that matches the work

Request or job ID

An application-controlled request or job ID identifies the unit of work, even when different workers handle different tasks over time. Logback’s MDC manual describes MDC as per-thread context, with operations affecting the current thread and its children: Logback MDC documentation.

Rank #2
Dell Optiplex 7050 SFF Desktop PC Intel i7-7700 4-Cores 3.60GHz 32GB DDR4 1TB SSD WiFi BT HDMI Duel Monitor Support Windows 11 Pro Excellent Condition(Renewed)
  • Model: Dell OptiPlex 7050 Small Form Factor (SFF)
  • Processor: Intel Core i7-7700 3.60 GHz
  • Memory: 32GB DDR4 Ram
  • Storage: 1TB Solid State Drive (SSD) Fast Boot + Storage
  • Operating System: Windows 11 Pro (64-bit)

Thread name

Thread names can help identify the executing worker, but they are not a reliable request boundary in server systems that recycle threads. A reused worker can process many unrelated requests, so using its name as the discriminator can group unrelated activity in one file. The Logback manual cautions about interpreting thread names in server environments: Logback MDC documentation.

Handle pooled and asynchronous work safely

MDC is thread-associated, so do not assume a value set on one thread will automatically be present in every executor task or asynchronous callback. Make sure the intended value is available on the thread that performs the logging, and remove or restore it when the task ends. Otherwise, a pooled worker may retain a previous task’s routing value and send later events to the wrong file.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Hewlett Packard Enterprise ProLiant MicroServer Gen11 Tower Server with Intel Xeon 6315P, 16GB DDR5, 4LFF Bays, 180W PSU (P86811-005)
  • 2.80 GHz processor speed ensures efficient operation with consistent reliability
  • Intel Xeon 2.80 GHz processor provides enterprise-grade performance with built-in security and remote management capabilities
  • Quad-core (4 Core) processor core helps server process data quickly and reliably for maximum productivity
  • 1 processors supported for faster processing and improved access to data, optimizing performance under heavy loads
  • With 16 GB memory, you can multitask between applications seamlessly, keeping productivity high and response times quick

For asynchronous logging, Logback documents that inexpensive event data, including thread name and MDC, is copied by default when the logging event is created. Set MDC before the logging call; changing it later does not change the already-created event’s context. See Logback asynchronous appender documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Plan for file and appender growth

Each distinct discriminator value may create a child appender and a corresponding file. Logback retires and removes a child appender after it has not been accessed for the configured timeout; the documented default stale timeout is 30 minutes. The documented default maxAppenderCount is Integer.MAX_VALUE, so do not assume the default meaningfully caps growth. See Logback SiftingAppender lifecycle and configuration.

Rank #4
HPE Hewlett Packard Enterprise ProLiant MicroServer Gen11 Tower Server, Intel Pentium Gold G7400 Processor, 16GB Memory, 1TB HDD Storage, External 180W US Power Supply Smart Choice P74439-005
  • MODEL P74439-005: Compact and affordable HPE ProLiant MicroServer Gen11 powered by Intel Pentium Gold G7400 3.7GHz processor, ideal for file sharing, NAS, and basic business workloads
  • READY OUT OF THE BOX: Includes 16GB DDR5 UDIMM memory (expandable to 128GB), one 1TB SATA 6G Business Critical HDD, embedded Intel VROC SATA, dedicated iLO-M.2 port kit, 180w external power adapter and 1/1/1 warranty for dependable plug-and-play server operation
  • WHISPER-QUIET & SPACE-SAVING: Ultra-compact mini tower design fits easily in small office spaces; supports wall, flat, or vertical placement for deployment flexibility
  • INTEGRATED REMOTE MANAGEMENT: Comes with HPE iLO 6 and embedded TPM 2.0 for secure, license-free remote server administration through shared port access
  • EXPANDABLE DESIGN: Two PCIe slots (including PCIe 5.0) and four LFF-NHP drive bays provide robust options for storage and component scalability. Features new MR408i-p controller support for enhanced storage performance
  • Use identifiers with an intentional scope and lifecycle, not an unbounded stream of arbitrary values.
  • Choose a stale-appender timeout and maximum count that fit the number of simultaneously active IDs and the application’s file-handling needs.
  • Consider whether a centralized log store with searchable request or job IDs is more manageable than maintaining a separate file for every ID.

The documented timeout and count are defaults, not performance guarantees. The right limits depend on the number of active identifiers and how long their appenders remain in use.

Best Value
HP Z4 G4 Workstation, Intel Xeon W-2133 (6-Core) up to 3.9GHz, 64GB DDR4, 512GB NVMe M.2 SSD + 2TB HDD, Nvidia Quadro P400 2GB, USB 3.1, Windows 11 Pro (Renewed)
  • HP Z4 G4 Workstation Tower
  • Intel Xeon W-2133 6-Core 3.6GHz (3.9GHz Turbo)
  • 64GB DDR4 Memory - Nvidia Quadro P400 2GB
  • 512GB NVMe M.2 SSD (boot) + 2TB HDD (storage)
  • Windows 11 Pro 64-bit

Check the routing when events land in the wrong file

  • Events go to unknown.log: confirm the configured MDC key exactly matches the key set in code, and that it is populated before logging.
  • Unrelated requests share a file: check whether the discriminator uses a recycled thread name or an identifier broader than one request or job.
  • A task inherits the prior task’s file: ensure task cleanup removes or restores the MDC value on pooled threads.
  • Files or active appenders accumulate: review identifier cardinality, timeout, and maxAppenderCount; a distinct value can create a distinct child appender.
  • Identifiers create unsafe paths: replace external or unsanitized input with a validated, application-controlled filename-safe value.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.