I was wondering if it is possible to ship MS Event logs from nxlog to Logstash directly without writing to disk first.
I'm trying to use file_cycle to clean up old NXLog files. When I start NXLog I see my log file "Demo.log" created and being written to. When my schedule executes I see the log file getting renamed to "Demo.log.1" but no new Demo.log file is created and NXLog still continues to write to the "Demo.log.1" file.
I'm not sure if I have something set incorrectly or if there is a bug. Here's the necessary bits from nxlog.conf:
This is a lengthy description but pelase bear with me, I'm really starting to loose hope here...
So I have tried to catch this "oversized string" and avoid it braking my logging but am not able to, even writing debug log failed.
Here is the nxlog.log where you can see that it broke at 5:30, then source log changed and then it broke again and after that it wrote no more to debug nor to syslog anything: