Configuring Options for sending Selective events


I am a newbie and trying to configure NXLog on a windows machine to forward logs to a syslog server. With the below configuration, all events are being forwarded to the server. we need only critical and error level events and only Security and System related events to be forwarded to the server. Below is my configuration:

AskedJune 7, 2016 - 12:00pm

How to Append (concatenate) additional data on the end of syslog messages?

How would I change the syslog event message on an output module so that every message gets an additional field?  I want to add another value called "Project X" after the message portion of all syslogs events/messages as they are forwarded to another server?  Would I use $raw_event as I show in my example? 

Current config:

<Output out>

   Module om_udp


   Port 514



Would I do this?

AskedJune 6, 2016 - 8:13pm

om_http authentication?

I am sending data to Elasticsearch via port 9200 and I am also using security for Elasticsearch. Any access to the rest API requiries authentication.

Is there a way to configure the om_http output to provide headers to authenticate when sending data to Elasticsearch?

Thank you

AskedJune 6, 2016 - 6:46pm

ASSERTION FAILED nx_module_output_fill_buffer

What this error means that leads some output modules to stop sending logs without crashing?


ASSERTION FAILED at line 21 in writerfuncs.c/nx_module_output_fill_buffer(): "output->buflen == 0" 

AskedJune 6, 2016 - 4:10pm