2
responses

Different ProcessID field values ​​in sysmon event

Hello!

I noticed that the value of the ProcessID field in sysmon event does not match the value of the ProcessID field which is nested in the Message field. Is it normal?

The sample sysmon event from https://nxlog.co/documentation/nxlog-user-guide/sysmon.html is bellow

AskedSeptember 24, 2020 - 11:38am
2
responses

im_msvistalog multiple filters

Hello,
I have to filter multiple log (such as System, Application) and also filter it by levels.
I'm trying to wrote a config but don't output anything.

AskedSeptember 11, 2020 - 2:18pm
2
responses

Windows 2012r2 (and possibly others) NXLog parsing issue?

Hello,

We are using NXLog extensively and just recently started seeing some parsing issues, so far specifically on Windows 2012r2 using Windows Event Forwarding, but could be others. It appears to be something with processing self-closed tags at first glance, but I've done a little bit of testing myself and couldn't directly reproduce the problem (so far), so figured I'd come here for guidance. Specific details are included below.

AskedOctober 31, 2019 - 1:12pm

Pages