onetime load of windows event file

This support forum board is for support questions relating to Nagios Log Server, our solution for managing and monitoring critical log data.
Locked
billy_strath
Posts: 19
Joined: Wed Nov 22, 2017 5:07 am

onetime load of windows event file

Post by billy_strath »

What is the best way to upload a windows archived event file, one time (ie I have a copy of security.evtx from a machine and I want to upload it to analyse it better? Is that using NXLog and pointing to the file or using shipper.py?
User avatar
cdienger
Support Tech
Posts: 5045
Joined: Tue Feb 07, 2017 11:26 am

Re: onetime load of windows event file

Post by cdienger »

Nxlog only seems to support uploading evtx files if you're using the Enterprise edition:

https://nxlog.co/products/additional-fe ... se-edition

It can still be used to upload the file if you're able to save the logs in a text format - csv for example. This method and using shipper would require some custom filters on the NLS side of things to make sure things were parsed correctly. I can look into this and get back to you as I think others would find it useful as well. If you're inclined to delve into this a bit more on your end, I suspect both https://assets.nagios.com/downloads/nag ... ilters.pdf and https://assets.nagios.com/downloads/nag ... -Files.pdf will be handy in setting this up.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.
billy_strath
Posts: 19
Joined: Wed Nov 22, 2017 5:07 am

Re: onetime load of windows event file

Post by billy_strath »

thanks. If I save as CSV I don't get all the rich info in the details of the event, so I think I have to look at the enterprise version of nxlog. Bit of a shame.
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: onetime load of windows event file

Post by scottwilkerson »

If this is a one-off, you can request a trial of the EE of NXLog that may be long enough for you to get this ingested
https://nxlog.co/products/nxlog-enterprise-edition
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
Locked