Windows 2012 R2 Having issues, while Windows 2008 works seamless

Tags:

#1 paulhurst

Trying to implement nxlog on a Windows 2012 R2 server and the log data appears to forward to Graylog3, however in a review of the data no messages are recieved. Using the same nxlog.conf file from a working 2008 server we get the same result.

#2 Zhengshi Nxlog ✓
#1 paulhurst
Trying to implement nxlog on a Windows 2012 R2 server and the log data appears to forward to Graylog3, however in a review of the data no messages are recieved. Using the same nxlog.conf file from a working 2008 server we get the same result.

Unfortunately there is not enough information to go on here. Lets see if we can address that.

What version of NXLog are you using on each system? The im_msvistalog module works the same on any 2008+ system.

Trying to implement nxlog on a Windows 2012 R2 server and the log data appears to forward to Graylog3, however in a review of the data no messages are recieved.

Are you getting events with no MSG field, or no events logged at all in graylog?
What is your config? i.e. what output modules and transforms are you using?
Have you checked wireshark/tcpdump/windump to see if the events are leaving the NXLog system?
Since these are two separate Windows servers, do they both have a clear shot to the Graylog server as far as networking is concerned? i.e. are the ports open along the path.