0
responses

XML Windows Logs + Rename + Resolver

Hi,

I can collect Security Events Windows in XML format and send them to my SIEM like i wanted

the result is here for an event 4624

AskedOctober 8, 2021 - 11:59am
2
responses

Possible to use nxlog to regularly check service status?

Hi,

We have the use case to get the specific service's status hourly and it could be done via some PowerShell commands. However, we don't want maintain the script in users' hosts and want to integrate the checking into nxlog's configuration. Does nxlog agent has the capability to run such command hourly? Or will there be any alternative method?

Many thanks in advance !

Best regards,
Steven

AskedSeptember 29, 2021 - 5:25am
1
response

Using NXLog to Netwitness

Hi,

The decoders used in Netwitness. The job of a decoder is to select a parser to parse log files.

The Netwitness LogDeconder shows Service Type as unknown but I was expecting to see winevent_snare.

My NXLog config uses the Exec $Message =~ s/(\t|\R)/ /g; to_syslog_snare(); to send windows log data to the NETWITNESS collector/decoder.

AskedSeptember 29, 2021 - 1:50am

Pages