Ask questions. Get answers. Find technical product solutions from passionate experts in the NXLog community.
Windows Event ID Whitelist Filter Question
paul.masek created
I'm using NXLog CE to forward Windows event logs via the im_msvistalog module. There's about 161 event id's that I want to whitelist from the security log and not send anything else from the event logs.
The following config snippet works:
<Input eventlog>
Module im_msvistalog
<QueryXML>
<QueryList>
<Query Id='0'>
<Select Path='Security'>*[System[(EventID=4627)]
or System[(EventID=4624)]
or System[(EventID=4775)]
or System[(EventID=4776)]
or System[(EventID=4777)]
or System[(EventID=4741)]
or System[(EventID=4742)]
or System[(EventID=4743)]
or System[(EventID=4744)]
or System[(EventID=4745)]
or System[(EventID=4746)]
or System[(EventID=4747)]
or System[(EventID=4748)]
or System[(EventID=4749)]
or System[(EventID=4750)]
or System[(EventID=4751)]
or System[(EventID=4752)]
or System[(EventID=4753)]
or System[(EventID=4759)]
or System[(EventID=4760)]
or System[(EventID=4672)]
or System[(EventID=4634)]
or System[(EventID=4648)]]
</Select>
</Query>
</QueryList>
</QueryXML>
</Input>
The issue is that once I add one more line to that config, NXLog stops shipping events completely.
Is there a better way for me to write this that would allow for more than 23 whitelisted event id's?
paul.masek created