2
responses

Hello,

I'm trying to query some EventID with a specific SeverityValue in "im_msvistalog", the config is something like this:

<Input eventlog>
Module im_msvistalog
<QueryXML>
<QueryList>
<Query Id='0'>
<Select Path='System'>*[System[(EventID=6005 or EventID=6008 or EventID=7036)]</Select>
</Query>
</QueryList>
</QueryXML>
Exec if $SeverityValue NOT IN (2, 4) drop();
Exec $Message =~ s/(\t|\R)/ /g;

I'm trying for a test to output on file, but nothing is outputted.

Anyone has some hint?

Thanks

AskedOctober 19, 2020 - 3:34pm

Answer (1)

Hi,

Could you provide your full conf file?

Regards,

Rafal

Comments (1)

  • LP_577584's picture

    Hello Rafal,

    Here's thee full conf

    <Input eventlog>
    Module im_msvistalog
    <QueryXML>
    <QueryList>
    <Query Id='0'>
    <Select Path='System'>*[System[(EventID=6005 or EventID=6008 or EventID=7036)]</Select>
    </Query>
    </QueryList>
    </QueryXML>
    Exec if $SeverityValue NOT IN (2, 4) drop();
    Exec $Message =~ s/(\t|\R)/ /g;
    </Input>

    <Output out>
    Module om_file
    File 'C:\Program Files (x86)\nxlog\data\out.log'
    Exec to_syslog_snare();
    </Output>

    <Route 1>
    Path eventlog => out
    </Route>