3
responses

Windows eventlog transfert

HI all, I am trying to transfer Windows eventlog (Securty, Application and System) from a server A to a server B. It is almost working if I send all the events of server A in a flat file on server B.
But my goal is a little bit different : I need to have the serverA-Events loggued in the eventviewer of the server B.
Do yo know if it is possible to achieve this ?
Thanks in advance !

AskedJune 6, 2016 - 1:14pm
1
response

NXLog for Performance Monitoring

There is a tone of infrastructure and application monitoring tools out there ( uberagent, vmturbo etc., powershell scirpts) to collect proccess details as their main task.

Allthough some could be integrated with NXLog ( lets say by using im_exec, or xm_exec) they have limited  filtering and output  capabilities compared to NXLog.

AskedJune 6, 2016 - 7:56am
11
responses

Windows .evt files to graylog

Has anyone succeed in sending .evt file content to graylog ?

Actually, I found that:

 - Using im_file module I can parse .evt file and send its content outside, but logs are bad formatted

 - Using im_vistalog module I can't parse .evt files only the Windows Event log, but logs are well formatted

Any advice someone ?

Maybe it is possible to send the ouput of im_file to im_vistalog ?

Thanks,
--
Mathieu

AskedJune 3, 2016 - 5:58pm
4
responses

Random nxlog crashes every now and then

Every now and then I get reports of logs not reporting. I investigate and 99.9% of the time, it is due to a loss of connectivity to the log server due to an nxlog crash. Typically, it is due to a faulting module, per Windows Event Viewer.

OS - Windows Server 2012 R2 Datacenter

NXLOG Version - How do I check?

Event Viewer ::

AskedJune 1, 2016 - 6:38pm
2
responses

Compile failure on FreeBSD - SSL error

I'm attempting to compile the latest nxlog on FreeBSD and it fails with the following error. Any thoughts as to a fix or workaround would be appreciated. My environment is as follows:

FreeBSD 10.1-STABLE

OpenSSL 1.0.2h  3 May 2016

AskedMay 31, 2016 - 4:19pm

Pages