+1
0
-1
1
answer

Issues on setting up NXLOG to accept syslogs on Windows

Hi!

I'm new to NXLOG so sorry if this is a dumb question.

So I have a Windows 2012 server that I'm attempting to set up to accept Syslog messages from an outsourced proxy system. I've been able to get NXLOG accept the logs and dump them to a flat file which our SIEM tool can pick up. However it ends up being a gigantic file... 

I'm trying to refine this now.

AskedFebruary 24, 2017 - 10:17pm
+1
0
-1
1
answer

How to efficiently clean up Windows DNS Server debug logs in nxlog

What is the most efficient way to parse Microsoft DNS Server debug logs into something more tidy, say into a CSV or KVP format on the nxlog agent?

Consider the following log message:

"24/02/2017 16:37:22 09B0 PACKET  0000009657E7BA40 UDP Rcv 10.0.100.15   a490   Q [0001   D   NOERROR] A      (7)example(3)com(0)"

First of all, what would be the most efficient way performance-wise to convert this into a CSV or KVP format?

AskedFebruary 24, 2017 - 3:59pm
+1
0
-1
1
answer

Logging suddenly stops for high-volume input but continues to work for low-volume input

I'm not sure how to characterize what's going on, but here goes...

My route path has two inputs, an itermittently high-volume input, and a low-volume input. The high-volume input can be thousands in a couple minutes, or it can be practically nothing. The low-volume input is, at most, one or two entries per ~3-4 minutes. There are also three outputs, two HTTP and a rotated file. They are disconnecting a fair bit, presumably due to timeouts or lack of pipelining or something.

AskedFebruary 20, 2017 - 6:20pm
+1
0
-1
1
answer

Convert DateTime to Unix TIme

Hello, I have question.

My variable $EventTime contains DateTime in only this format "2017-12-30 01:30:00"
How me with use NxLog, convert to UNIX TIME format or convert to this format  Dec 30 01:30:00.

Thank

AskedFebruary 18, 2017 - 12:44pm

Pages