csv to syslog (Linux) - Cisco Umbrella files.


I have about 3 days of experience with NXLog and what I am attempting to do is pull Cisco Umbrella Logs via an s3fs mount, unzip them and then read the logs using nxlog.

I am still working out the specifics of how to get all the logs unzipped and into one working file but my test file is failing to be read and sent to the syslog server.

I have taken a new nxlog.conf and set it up with the following:

AskedFebruary 24, 2018 - 10:39pm

Nxlog syntax for capturing Windows Event Viewer logs

Hello, I am using NXLOG to capture windows event viewer logs . I have below requirements
(1) Forward Event ID 4624 events
(2) Forward Event ID 4689 events only for a specific process name (say notepad.exe) . By default 4689 is common to many processes.

AskedFebruary 21, 2018 - 6:02pm

database log severity.

Hello There,

I'm working on customer poc that to collect database log and convert it to syslog to send another monitoring tool.

the om_file working as expect, but there are only send on info severity. it there any way that I can process that db log format and make it have severity in syslog ?

thank you , Kriengsak

AskedFebruary 20, 2018 - 12:55pm

How to parse JSON logs to syslog format?

nxlog-ce-2.9.1716 Ubuntu 16.04 LTS (OS)

I am trying to parse JSON to SYSLOG

There are two issues. 1. the NoCache TRUE does not seem to work. (I also tried SavePOS false) and it always caches the file.

  1. When I do get it to work; it uses the localhost (which is not where the logs are from) and the time/date stamp from the JSON file (but no other data is there).

Is there an example of parsing JSON to _syslog_bsd()? for forwarding to a SEIM

AskedFebruary 16, 2018 - 4:06am