- OS Support
- Enterprise Edition Reference Manual
- 132. Man Pages
- 133. Configuration
- 134. Language
- 135. Extension Modules
- 136. Input Modules
- 136.1. Process Accounting (im_acct)
- 136.2. AIX Auditing (im_aixaudit)
- 136.3. Azure (im_azure)
- 136.4. Batched Compression (im_batchcompress)
- 136.5. Basic Security Module Auditing (im_bsm)
- 136.6. Check Point OPSEC LEA (im_checkpoint)
- 136.7. DBI (im_dbi)
- 136.8. Event Tracing for Windows (im_etw)
- 136.9. External Programs (im_exec)
- 136.10. Files (im_file)
- 136.11. File Integrity Monitoring (im_fim)
- 136.12. Go (im_go)
- 136.13. HTTP(s) (im_http)
- 136.14. Internal (im_internal)
- 136.15. Java (im_java)
- 136.16. Kafka (im_kafka)
- 136.17. Kernel (im_kernel)
- 136.18. Linux Audit System (im_linuxaudit)
- 136.19. macOS ULS (im_maculs)
- 136.20. Mark (im_mark)
- 136.21. EventLog for Windows XP/2000/2003 (im_mseventlog)
- 136.22. Event Log for Windows 2008/Vista and later (im_msvistalog)
- 136.23. Null (im_null)
- 136.24. ODBC (im_odbc)
- 136.25. Packet Capture (im_pcap)
- 136.26. Perl (im_perl)
- 136.27. Named Pipes (im_pipe)
- 136.28. Python (im_python)
- 136.29. Redis (im_redis)
- 136.30. Windows Registry Monitoring (im_regmon)
- 136.31. Ruby (im_ruby)
- 136.32. TLS/SSL (im_ssl)
- 136.33. Systemd (im_systemd)
- 136.34. TCP (im_tcp)
- 136.35. Test Generator (im_testgen)
- 136.36. UDP (im_udp)
- 136.37. Unix Domain Sockets (im_uds)
- 136.38. Windows Performance Counters (im_winperfcount)
- 136.39. Windows Event Collector (im_wseventing)
- 136.40. ZeroMQ (im_zmq)
- 137. Processor Modules
- 138. Output Modules
- NXLog Manager
- NXLog Add-Ons
This module can be used to collect EventLog messages on Microsoft
Windows platforms. The module looks up the available EventLog sources
stored under the registry key
SYSTEM\CurrentControlSet\Services\Eventlog and polls logs from
each of these sources or only the sources defined with the
|To examine the supported platforms, see the list of installer packages in the Available Modules chapter.|
Windows Vista, Windows 2008, and later use a new EventLog API which is
not backward compatible. Messages in some events produced by sources
in this new format cannot be resolved with the old API which is used
by this module. If such an event is encountered, a
Though the majority of event messages can be read with this module even on Windows 2008/Vista and later, it is recommended to use the im_msvistalog module instead.
Strings are stored in DLL and executable files and need to be read by the module when reading EventLog messages. If a program (DLL/EXE) is already uninstalled and is not available for looking up a string, the following message will appear instead:
The description for EventID XXXX from source SOURCE cannot be found.
The im_mseventlog module accepts the following directives in addition to the common module directives.
This optional boolean directive instructs the module to only read logs which arrived after NXLog was started if the saved position could not be read (for example on first start). When SavePos is TRUE and a previously saved position value could be read, the module will resume reading from this saved position. If ReadFromLast is FALSE, the module will read all logs from the EventLog. This can result in quite a lot of messages, and is usually not the expected behavior. If this directive is not specified, it defaults to TRUE.
This boolean directive specifies that the file position should be saved when NXLog exits. The file position will be read from the cache file upon startup. The default is TRUE: the file position will be saved if this directive is not specified. Even if SavePos is enabled, it can be explicitly turned off with the global NoCache directive.
This optional directive takes a comma-separated list of EventLog filenames, such as
Security, Application, to select specific EventLog sources for reading. If this directive is not specified, then all available EventLog sources are read (as listed in the registry). This directive should not be confused with the $SourceName field contained within the EventLog and it is not a list of such names. The value of this is stored in the FileName field.
If this optional boolean directive is set to TRUE, all strings will be converted to UTF-8 encoding. Internally this calls the convert_fields procedure. The xm_charconv module must be loaded for the character set conversion to work. The default is TRUE, but conversion will only occur if the xm_charconv module is loaded, otherwise strings will be in the local codepage.
The following fields are used by im_mseventlog.
A list of event fields in key-value pairs.
The username associated with the event.
The type of the account. Possible values are:
Well Known Group,
The category name resolved from CategoryNumber.
The category number, stored as Category in the EventRecord.
The domain name of the user.
The event ID of the EventRecord.
The TimeGenerated field of the EventRecord.
The TimeWritten field of the EventRecord.
The type of the event, which is a string describing the severity. Possible values are:
The logfile source of the event (for example,
The host or computer name field of the EventRecord.
The message from the event.
The number of the event record.
The normalized severity number of the event, mapped as follows.
Event Log Severity Normalized Severity
The event source which produced the event (the subsystem or application name).