+1
0
-1
1
answer

Filtering to specific logs

All,

I'm somewhat new to Netwrix, and I need some help understanding how I can send ONLY specific logs up to our SEIM.  I've dug through the documentation a bit, and will continue to do so.  I'm sure someone on here can whip up a quick response...

Here is my config file, please help me with mocking up a config that will only send up events 4648 and 4624...

AskedOctober 17, 2016 - 6:56pm
+1
0
-1
1
answer

Log rotation

What is the best way to do a log rotation?

I'm using fileop and I wanted log rotation at midnight, but it hasn't been working. Would it be better to move the Schedule to the Output section?

<Extension fileop>
    Module      xm_fileop

AskedOctober 17, 2016 - 5:10pm
+1
0
-1
0
answers

Logon vs. Logoff Events to SEIM

All,

I'm struggling with NXLOG forwarding events to our SEIM.  I'm able to see Logoff (4647) events, but not Logon (4624) events.  Under the WIndows Event Log, we see both events occuring as expected, but our SEIM is only getting Logoffs...

Our config file is standard, but here it is below...

AskedOctober 12, 2016 - 9:13pm
+1
0
-1
1
answer

Unable to replace Windows new line characters and tabs when using to_json

I am unable to replace \r\n and \t when using to_json. When using to_syslog_bsd I can replace them, but not with JSON. Do I have an error in my config or is this a bug?

## Please set the ROOT to the folder your nxlog was installed into,
## otherwise it will not start.

#define ROOT C:\Program Files\nxlog
define ROOT C:\Program Files (x86)\nxlog

AskedOctober 12, 2016 - 1:26am

Pages