Windows  |  Telemetry collection  |  Telemetry auditing

Windows Task Scheduler event IDs: auditing scheduled task creation and abuse

Windows records scheduled task activity in two separate event logs. The Security log holds event IDs 4698-4702, covering task creation, deletion, turning on, turning off, and updates, with the full task definition XML attached. The Microsoft-Windows-TaskScheduler/Operational log holds event IDs 106, 140, and 141 for registration changes, plus 100, 200, and 201 for execution. Windows doesn’t switch on either source by default: Microsoft’s own Tarrask analysis states that "neither of these are audited by default and must be explicitly turned on by an administrator.

Releases  |  NXLog Platform

Announcing NXLog Platform 1.14

We are happy to announce the latest release of NXLog Platform, version 1.14. This update adds an entitlements usage summary to the NXLog Platform UI and extends NXLog Agent support to the newest Ubuntu 26.04 LTS release and Red Hat Enterprise Linux 5 for long-lived legacy deployments. Read on for more details about these updates. See data source entitlements and usage at a glance NXLog Platform 1.14 adds entitlements usage visibility to the NXLog Platform UI, giving you a clear breakdown of how your data source license is used without contacting support.

Releases  |  NXLog Agent  |  Red Hat  |  Critical infrastructure

NXLog Agent 6.15 adds RHEL 5 support: log collection for the systems you can't upgrade

Some of the most critical systems in your infrastructure are also the oldest. If you operate in energy, manufacturing, or government, chances are you have hosts still running Red Hat Enterprise Linux 5 or CentOS 5. Not because anyone forgot to upgrade them, but because upgrading them is not an option. The OS is frozen by compliance requirements, tied to certified industrial equipment, or locked to software that would break on anything newer.

syslog  |  Telemetry collection  |  Log aggregation

Free syslog server and viewer: setup, limitations, and when to upgrade

You can centralize logs from firewalls, switches, and Linux hosts with a free syslog server - rsyslog, syslog-ng OSE, and the free plan of NXLog Platform all do the job. The real differences show up in Windows support, secure transport, viewers, and what happens when your environment grows. A firewall, a switch, or an auditor says "send your logs somewhere," and there’s no budget line for it. A free syslog server solves the immediate problem in an afternoon.

Log analysis  |  Telemetry collection  |  Centralized logging

Firewall log analyzer: How to centralize and analyze firewall logs

Your firewalls already record allowed and denied connections and policy changes. Each vendor logs them in its own format. This post shows you how to get those records into one searchable structure, with working configurations for the most common sources. A firewall log analyzer is a tool that collects logs from firewalls, parses each vendor’s log format into structured fields, and stores the results in one place for searching, alerting, and reporting.

Log analysis  |  Telemetry collection  |  Centralized logging

Server log analysis: collection, parsing, monitoring, and troubleshooting

Server log analysis turns the raw event records your Windows and Linux servers already produce into security detections, audit evidence, and troubleshooting answers. NXLog Agent and NXLog Platform provide that pipeline: collection and parsing at the source, centralized storage and search on top. Every server you run writes down what happens to it: who logged in, which services started, what the web server returned, why a process crashed. Attackers know this too.

More

Sysmon event IDs: what to collect for threat detection

Surviving a region outage: multi-region disaster recovery for NXLog Platform on AWS

Log collection tools: 5 options compared for security operations

What is syslog? Ports, severity levels, and RFC 3164 vs. RFC 5424

All Posts