Change Syslog Facility when reading/forwarding windows events.

Just installed nxlog to begin forwarding events to AlienVault, everything seems to be working so far with reading and forwarding events from the windows log using the im_msvistalog module.  One thing we would like to change to set the Syslog Facility before forwarding it AlienVault.  Have been unable to locate how to do so.

AskedJanuary 21, 2015 - 4:05pm

Windows: Auto Start of nxlog service after the install



I noticed the NXlog service is not started at the end of the install process. I would the service to start automatically at the end of the install of the MSI.

Our goal is:

- modify the conf file in the MSI file to have it ready out of the box.

- Deploy with GPO on all servers.

AskedJanuary 13, 2015 - 8:16am

Inconsistent log sending from windows to graylog2



We are using the community edition of nxlog 2.8.1248 on windows 2008 R2 server. We are having forwarding event log and IIS logs to graylog2.

This is the conf file is pasted below.

AskedJanuary 9, 2015 - 5:12pm

Unnecessary syslog header was recorded from 0:00 to 9:00 on Jan 1, 2015 of JST(UTC+9:00)

Unnecessary syslog header was recorded from 0:00 to 9:00 on Jan 1, 2015 of JST(UTC+9:00).

<133>Dec 31 23:55:04 OTSS0101 OTxx01xx: warning
<133>Jan  1 00:20:12 Jan 01 00:21:51 OTSS0101 OTxx01xx: critical
<133>Jan  1 08:00:15 Jan 01 08:01:52 OTSS0101 OTxx01xx: critical
<133>Jan  1 09:01:51 OTSS0101 OTxx01xx: critical

AskedJanuary 6, 2015 - 8:54am