+1
0
-1
1
answer

Getting the correct select path setup

I am wanting to see if this is possiable to put in a line for Input event log. 

 

 <Input eventlog>   

Module im_msvistalog   

SavePos FALSE   

ReadFromLast TRUE   

Query  <QueryList>\            

<Query Id="0">\             

<Select Path="System">*[System[(EventID=22 or EventID=1076 or EventID=6005 or EventID=6006)]] and *[System/Level=2]</Select>\             

</Query>\

AskedNovember 15, 2016 - 10:05pm
+1
0
-1
1
answer

Creating Stream with API

Hello. 

The case is:

I am creating Stream with rules using API.

Question is:

Is there a way to set the input for a stream using GrayLog API?

 

Thanks.

AskedNovember 11, 2016 - 2:44pm
+1
0
-1
1
answer

om_file to write in .evtx files

Hi,

I want to store my logs in .evtx file in windows. I tried following configuration.

<Output out2>    
    Module      om_file
  File     '%ROOT%\tmp\test.evtx'

</Output>

This created evtx file but it was also opening with notepad, wordpad,etc. For security purpose, I want to make it open with MS EventViewer API only.

Is this possible using nxlog om_file module? Is there any plugin for nxlog to store data in .evtx files?

AskedNovember 9, 2016 - 11:23am
+1
0
-1
1
answer

Installation Command Line Arguments

Hi,

I am a new at this and would like to know the command line argument that will let me specify what config file to use. I need to have this done during installation and avoid changing the file post installation.

Any help would be greatly appreciated.

 

Thanks.

AskedNovember 7, 2016 - 11:05pm

Pages