1
response

Two related threads I found on this

Posted a question the Windows forums as well

There are domain controllers that a logging server connects to using Windows Eventlog Forwarding (poll).

In the eventlog eventid 4624 comes in but in the message field its all % placeholders but the XML data is correct. Before some patching the xml data was broken.

The Data fields looked like this

 <Data Name="AuthenticationPackageName">Kerberos</Data> 
  <Data Name="WorkstationName"> 
    <Data Name="LogonGuid">{B3A61084-7036-1568-AFB2-3290B7F943F9}</Data> 
  </Data>
  <Data Name="TransmittedServices">-</Data> 
  <Data Name="LmPackageName">-</Data> 

But now are more correct and look like this

 <Data Name="AuthenticationPackageName">Kerberos</Data> 
  <Data Name="WorkstationName" /> 
  <Data Name="LogonGuid">{B3A61084-7036-1568-AFB2-3290B7F943F9}</Data> 
  <Data Name="TransmittedServices">-</Data> 
  <Data Name="LmPackageName">-</Data> 

The issue is only when nothing is in the WorktationName field.

NXlog reads this and converts to JSON and thats where NXlog is obviosly having problems

The JSON looks like this

"AuthenticationPackageName":"Kerberos","WorkstationName' /> <Data Name='LogonGuid":"{B3A6.....

So at the workstation name it fails to parse the XML, possibly because the XML field is closed with /> instead of a full </Data>

Another issue is that the Message field does not come through NXlog at all.

Would love to get some help debugging this.

AskedOctober 13, 2016 - 6:32pm

Answer (1)