how to add a field depending on different judgment statement

Hi All,

   I use nxlog-ce-2.9.1504 to read log and parse it,the format of log is like:

20160523 10:58:22 sda              0      0    0    0      14      2    2    9       9     1     1      0    0

20160523 10:58:22 sdb              0      3    2    0      20      4    8    4       2     5     1      7    2

I want get the purpose:

AskedMay 23, 2016 - 8:18am

Basic question about NXLOG file transfert configuration

Hi all,

I am new with NXLOG and I have a very basic question to ask you : is it possible to simply copy a file from server A (source file name : c:\osit\log\df_mon.log) to server B (target file name : c:\osit\log15\df_mon.log). I spent already hours on NXLOG config file but I was not able to make it worked because the instruction "File" seeems not to be compatible wit the "om_tcp" output modeule and Host/Port settings.

Thanks a lot in advance, Sophie

AskedMay 21, 2016 - 8:29pm

Tomcat Catalina, today date on filename

Hi everyboy,

I have a log rotation folder on catalina application with a filename based on date like that "catalina.2016-04-15.log". Catalina create a log file with the date of the day, only if he need to write log (not automatically a file per day).

Some one has a exemple for configure NX log ?


Thanks in advance !



AskedMay 20, 2016 - 4:05pm

om_http unexpected data from server causes nxlog service to crash

I have the usual error "Unexpected data from server ..." using om_http to send Windows event logs through Nginx to Redis.

The problem is that when randomly this error happens ( once every 5 days) the service unexpectently stops !

From the source code I can understand that NXLog receives a response which cannot map to a correnponding request.

AskedMay 19, 2016 - 8:18am

Exec if $EventID NOT IN - Question on placement in config.

Would this be the correct placement to add the filter event ID string?  Should anything esle be commented out?

#Windows Event Logging of Security,System and Application Logs  

Module      im_mseventlog  

Exec to_syslog_snare();

Exec if $EventID NOT IN (528, 529, 567, 592, 601, 602, 608, 612, 636, 7034, 7035, 7036, 7040, 4097, 64004, 2, 3005) drop();





AskedMay 17, 2016 - 4:54pm