Ask questions. Get answers. Find technical product solutions from passionate experts in the NXLog community.
im_msvistalog multiple filters
LP_577584 created
Hello,
I have to filter multiple log (such as System, Application) and also filter it by levels.
I'm trying to wrote a config but don't output anything.
<Input eventlog>
Module im_msvistalog
<QueryXML>
<QueryList>
<Query Id='0'>
<Select Path="System">[System[(EventID=11150 or EventID=11151 or EventID=11152 or EventID=11153 or EventID=11154 or EventID=11155 or EventID=11162 or EventID=11163 or EventID=11164 or EventID=11165 or EventID=11166 or EventID=11167 or EventID=5773 or EventID=5774)]]</Select>
<Select Path='System'>[System/Level=2]</Select>
<Select Path="System">[System[(Level=2 or Level=4)][(EventID=6005 or EventID=6008)]]</Select>
<Select Path="System">[System/Level=4[(EventID=6005 or EventID=6008)]]</Select>s
<Select Path="System">[System/Level=3[(EventID=1031 or EventID=1053 or EventID=5053 or EventID=1129 or EventID=1131 or EventID=1135 or EventID=1206 or EventID=1211 or EventID=1216 or EventID=1553 or EventID=5553 or EventID=2057 or EventID=47 or EventID=16947 or EventID=16949 or EventID=4034 or EventID=9015 or EventID=9026)]]</Select>
<Select Path="Application">[System/Level=2]</Select>
<Select Path="Application">*[System/Level=3[(EventID=514)]]</Select>
</QueryList>
</QueryXML>
I don't know if is the right way, it's my first time with nxlog.
Thanks a lot!
LP_577584 created
Windows event filtering not working? Or something else
DamnPeggy created
Hello, I have recently been trying up a syslog-ng server for various devices and have tried a couple of things for sending Windows Events to the server.
Finally decieded that NXLog will do what I need and I have gotten sent some events over without much configuration, but when trying filter within the .conf file, it always fails.
I can't really find much good information as to why it might be failing, as it seems that it should be correct.(to me anyway)
# Windows Event Log,
<Input s_eventlog>
Module im_msvistalog
Exec if $EventID == 4734 or $EventID == 4624 drop();
Exec $Message = to_json();
</Input>
I have narrowed it down to this block, since the log says
nxlog failed to start: </Input> without matching <Input> section at C:\Program Files (x86)\nxlog\conf\nxlog.conf:43
Which is where this block ends?
I can't really make sense of this, so if anyone has some guidance please tell me.
DamnPeggy created