+1
0
-1
1
answer

ERROR apr_stat failed on old log files

Occasionally I will see error like this in the nxlog.log:

2017-04-13 10:18:43 ERROR apr_stat failed on file C:\inetpub\logs\IIS\\W3SVC1\u_extend1776_x.log; Access is denied.

What concerns me is that while this error was recorded at 10:18 the log it failed to access (u_extend1776_x.log) is like 3 hours old!

Does this mean nxlog is wayyy backlogged and is 3 hours behind in processing logs in this folder?

AskedApril 13, 2017 - 4:42pm
+1
0
-1
1
answer

How can I see what file nxlog is currently processing?

Without turning on debugging, is there a way to know which file nxlog is currently processing?

I want to track how far it is behind new logs getting created. Its working fine right now, but I want to be able to track this over time and see how it changes- so leaving debugging turned on wont work.

AskedApril 13, 2017 - 3:59pm
+1
0
-1
1
answer

Cannot parse properly Exchange # lines

I do use NXLog to parse the Exchange logs and send them to my Graylog.  Time to time, Graylog still receive the line #Software: Microsoft Exchange...   

Note that the line is sent once per hours or two hours. 

It seems that the check if $raw_event =~ /^#/ drop(); fail to drop the #line randomly.

Bellow part of my config for the input:

<Input in_MSGTRK>

AskedApril 13, 2017 - 10:17am
+1
0
-1
1
answer

Using om_redis with mulitple output servers

Hey!

I have a bunch of log data that I'd like to push to a set of redis instances that are used as a queue.  In an ideal world, I could use a config like this:

<Output redis-out>
    Command LPUSH
    Host server1,server2,server3
</Output>

The desired result is that nxlog pushes sequential lines to each of the servers in turn - no duplication, just load distribution.

AskedApril 12, 2017 - 1:39am

Pages