I'm using NXlog CE 2.10.2102 on a Win 2012 R2 x64 server to collect both the four default Windows logs and the Forwarded Events snd send to a Syslog server as Snare formatted. However, some events only contains their System segment, missing their entire EventData. For example, all of events 1000 and 1001 and all 4624 events with Kerberos login. 4624 with Advapi are passed just fine. I've no idea why is that, every idea would be welcomed.
Here's my configuration:
define ROOT C:\Program Files (x86)\nxlog
$Message =~ s/(\t|\R)/ /g; to_syslog_snare();
Path in => out