7
responses

noob question regarding queries

hi, i try to use special event ids to with graylog but its not working. service is running, so imho it could not be a syntax error in the config.my query looks like

AskedOctober 13, 2017 - 10:04am
1
response

Getting the correct select path setup

I am wanting to see if this is possiable to put in a line for Input event log. 

 

 <Input eventlog>   

Module im_msvistalog   

SavePos FALSE   

ReadFromLast TRUE   

Query  <QueryList>\            

<Query Id="0">\             

<Select Path="System">*[System[(EventID=22 or EventID=1076 or EventID=6005 or EventID=6006)]] and *[System/Level=2]</Select>\             

</Query>\

AskedNovember 15, 2016 - 10:05pm
1
response

NXLog on Windows server 2003 (im_mseventlog) invalid keyword: Query problem

Hi,

I have installed NXLog on Windows server 2003 with this configuration (example from NXLog reference manual)

<Input in>

#    Module      im_msvistalog

# For windows 2003 and earlier use the following:

Module      im_mseventlog

 Query <QueryList> <Query Id="0"> <Select Path="Security">*</Select> </Query> </Querylist>

 </Input>

AskedNovember 27, 2015 - 11:19am