Import .evt files
Is there a way to import .evt files with nxlog? Using im_file doesn't throw errors, but data doesnt seem to ship.
I also tried using:
module im_mseventlog file "file_path"
but that didn't work either.
Thanks for your help.
Please see the manual for descriptions of the directives.
Note that in this example I have everything in the default locations.
To find the event log files, right click on the logs inside of EventLog and choose properties.
System, this gave me
<Input eventlog> Module im_msvistalog File C:\Windows\System32\winevt\Logs\system.evtx </Input> <Output output> Module om_file File "C:\Windows\Temp\evt.log" Exec to_json(); </Output>
If this is not working for you, it is possible that the path is incorrect or there is something else going on. In the case of errors,
nxlog.log should produce something to go off of, or running the service from command line with
nxlog -f after stopping the service
sc stop nxlog.