NXLog User Guide
- OS Support
- Enterprise Edition Reference Manual
- 146. Man Pages
- 147. Configuration
- 148. Language
- 149. Extension Modules
- 150. Input Modules
- 150.1. Process accounting (im_acct)
- 150.2. AIX auditing (im_aixaudit)
- 150.3. Azure (im_azure)
- 150.4. Batched compression (im_batchcompress)
- 150.5. Basic Security Module Auditing (im_bsm)
- 150.6. Check Point OPSEC LEA (im_checkpoint)
- 150.7. DBI (im_dbi)
- 150.8. Event Tracing for Windows (im_etw)
- 150.9. External programs (im_exec)
- 150.10. File (im_file)
- 150.11. File integrity monitoring (im_fim)
- 150.12. Go (im_go)
- 150.13. HTTP(s) (im_http)
- 150.14. Internal (im_internal)
- 150.15. Java (im_java)
- 150.16. Kafka (im_kafka)
- 150.17. Kernel (im_kernel)
- 150.18. Linux Audit System (im_linuxaudit)
- 150.19. macOS Endpoint Security (im_maces)
- 150.20. macOS ULS (im_maculs)
- 150.21. Mark (im_mark)
- 150.22. Event Logging for Windows XP/2000/2003 (im_mseventlog)
- 150.23. Event log for Windows 2008/Vista and later (im_msvistalog)
- 150.24. Null (im_null)
- 150.25. ODBC (im_odbc)
- 150.26. Packet capture (im_pcap)
- 150.27. Perl (im_perl)
- 150.28. Named pipes (im_pipe)
- 150.29. Python (im_python)
- 150.30. Redis (im_redis)
- 150.31. Windows Registry Monitoring (im_regmon)
- 150.32. Ruby (im_ruby)
- 150.33. TLS/SSL (im_ssl)
- 150.34. Systemd (im_systemd)
- 150.35. TCP (im_tcp)
- 150.36. Test Generator (im_testgen)
- 150.37. UDP (im_udp)
- 150.38. Unix domain sockets (im_uds)
- 150.39. Windows Performance Counters (im_winperfcount)
- 150.40. Windows Event Collector (im_wseventing)
- 150.41. ZeroMQ (im_zmq)
- 151. Processor Modules
- 152. Output Modules
- NXLog Manager
- NXLog Add-Ons
This module accepts TCP connections on the configured address and port. It can handle multiple simultaneous connections. The TCP transfer protocol provides more reliable log transmission than UDP. If security is a concern, consider using the im_ssl module instead.
|To examine the supported platforms, see the list of installer packages in the Available Modules chapter.|
|This module provides no access control. Firewall rules can be used to deny connections from certain hosts.|
The im_tcp module accepts the following directives in addition to the common module directives.
The module will accept connections on this IP address or DNS hostname. For security, the default listen address is
localhost(the localhost loopback address is not accessible from the outside). To receive logs from remote hosts, the address specified here must be accessible. The any address
0.0.0.0is commonly used here.
The port number can be defined by appending it at the end of the hostname or IP address using a colon as a separator (
host:port). IPv6 addresses must be enclosed in square brackets (
[host]:port). The port section of this directive and the Port directive are mutually exclusive. In case both are defined, the port number defined here takes precedence over a port defined in the Port directive. In case none of them is defined, the default port 514 is used.
To listen on multiple addresses or ports in a single module instance, this directive can be repeated multiple times. Both IPv4 and IPv6 addresses are supported. If a DNS name is used, the number of addresses or cnames should be kept below 16 to avoid potential issues caused by DNS response size limits.
|Formerly called Host, this directive is now ListenAddr. Host for incoming traffic will become deprecated from NXLog EE 6.0.|
When a hostname is used as the
For client applications that don’t support IPv6, to avoid the behavior
described above the
Alternatively, the server-side system may be configured to prioritize IPv4
addresses for the hostname specified by the
For more information see the Microsoft documentation on Configuring IPv6 in Windows for advanced users.
This limitation will be addressed in a future release by making listening modules bind to all available IPv4/IPv6 addresses that a hostname resolves to.
The module will listen for incoming connections on this port number. The default port is 514 if this directive is not specified.
|The Port directive will become deprecated from NXLog EE 6.0. After that, the port can only be defined in the ListenAddr directive.|
This optional directive may be used to specify a whitelist of IP addresses and/or networks that are allowed to connect. The directive can be specified more than once to add different IPs or networks to the whitelist. This directive is only active when the Listen or ListenAddr directives are present. In the absence of this directive, there is no restriction on the hosts which may connect to a listening module. The following formats may be used:
0.0.0.0/32(IPv4 network with subnet bits)
0.0.0.0/0.0.0.0(IPv4 network with subnet address)
aa::12/64(IPv6 network with subnet bits)
This optional boolean directive enables synchronous listening on the same port by multiple module instances. Each module instance runs in its own thread, allowing NXLog to process incoming data simultaneously to take better advantage of multiprocessor systems. The default value is FALSE.
To enable synchronous listening, the configuration file should contain multiple im_tcp module instances listening on the same port and the ReusePort directive set to TRUE, see the Examples section.
The following fields are used by im_tcp.
The received string.
The IP address of the remote host.
Pre-v5 syntax examples are included, they will become invalid with NXLog EE 6.0.
With this configuration, NXLog listens for TCP connections on port 1514 and writes the received log messages to a file.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 <Input tcp> Module im_tcp ListenAddr 0.0.0.0:1514 </Input> # Using the syntax prior to NXLog EE 5, # where the port is defined in a separate directive. #<Input tcp> # Module im_tcp # Host 0.0.0.0 # Port 1514 #</Input> <Output file> Module om_file File "tmp/output" </Output> <Route tcp_to_file> Path tcp => file </Route>
The configuration below provides two im_tcp module instances to reuse
port 1514 via the ReusePort directive.
Received messages are written to the
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 <Input tcp_one> Module im_tcp ListenAddr 192.168.31.11:1514 ReusePort TRUE </Input> <Input tcp_two> Module im_tcp ListenAddr 192.168.31.11:1514 ReusePort TRUE </Input> # Using the syntax prior to NXLog EE 5, # where the port is defined in a separate directive. #<Input tcp_one> # Module im_tcp # Host 192.168.31.11 # Port 1514 # ReusePort TRUE #/Input> # #<Input tcp_two> # Module im_tcp # Host 192.168.31.11 # Port 1514 # ReusePort TRUE #</Input>