1
answer

Set default interface to send.

Hello
I have a server that send logs (with nxlog-ce), that has 3 network interface (3 differents IPs). So any time that reboot server, I see (on my SIEM) incoming logs from a different IP. Is there a way to set on nxlog the default interface?

AskedJanuary 10, 2019 - 10:17pm
1
answer

Nxlog CE agent forwarding all Windows Events despite the query level filter

Hello everybody, I'm trying to filter Windows events log with severity/level only from warning to critical, so from level 1 to 3.

Unfortunately, I tried several configurations, but the agent is still forwarding all the events. Like if there were no filters.

My specifications are, Nxlog CE Agent (version 2.10.2102) on a Windows 10 64 bits build 1803 with this conf :

AskedDecember 6, 2018 - 3:22pm
1
answer

Recursive file_remove

Is there any way to recursively delete files with file_remove?

I have applications logging in the following structure:

  • D:\Applogs\App1\Access-3172016.log
  • D:\Applogs\App2\Access-3162016.log

We're able to define an input and collect the logs no problem with the following definition:

<Input Access_Logs>

AskedMarch 17, 2016 - 9:30pm

Pages