0
answers

Trying to implement nxlog on a Windows 2012 R2 server and the log data appears to forward to Graylog3, however in a review of the data no messages are recieved.
Using the same nxlog.conf file from a working 2008 server we get the same result.

AskedAugust 9, 2019 - 11:08pm

Comments (1)

  • Zhengshi's picture
    (NXLog)

    Unfortunately there is not enough information to go on here. Lets see if we can address that.

    What version of NXLog are you using on each system? The im_msvistalog module works the same on any 2008+ system.

    Trying to implement nxlog on a Windows 2012 R2 server and the log data appears to forward to Graylog3, however in a review of the data no messages are recieved.

    Are you getting events with no MSG field, or no events logged at all in graylog?
    What is your config? i.e. what output modules and transforms are you using?
    Have you checked wireshark/tcpdump/windump to see if the events are leaving the NXLog system?
    Since these are two separate Windows servers, do they both have a clear shot to the Graylog server as far as networking is concerned? i.e. are the ports open along the path.

    August 10, 2019 - 11:39pm

Answers (0)