we have a rather small Nagios Log Server setup with 1 instance/server (v2.1.6) and 33 windows host sending windows event logs with nxlog (v2.9.1716).
we have all 33 hosts sending logs find until, all of sudden a single or a few hosts stop sending their logs.
the only thing that seemed to have worked so far is rebooting the Nagios log server, then it works for a couple of days and then some other hosts stops sending.
I have taken over this system from a former collegue so i am rather new at Nagios Log Server, not sure what i am looking for.
The nxlog datalog show this error, but that is also in on the hosts that work:
Code: Select all
2020-05-18 10:45:29 WARNING stopping nxlog service
2020-05-18 10:45:29 WARNING nxlog-ce received a termination request signal, exiting...
2020-05-18 10:45:31 INFO connecting to 172.17.9.58:3515
2020-05-18 10:45:31 INFO nxlog-ce-2.9.1716 started
2020-05-18 10:45:32 WARNING Due to a limitation in the Windows EventLog subsystem, a query cannot contain more than 256 sources.
2020-05-18 10:45:32 WARNING The following sources are omitted to avoid exceeding the limit in the generated query: Microsoft-Windows-SMBWitnessClient/Informational Microsoft-Windows-StateRepository/Operational Microsoft-Windows-StateRepository/Restricted Microsoft-Windows-Storage-ClassPnP/Operational Microsoft-Windows-Storage-Storport/Operational Microsoft-Windows-Storage-Tiering/Admin Microsoft-Windows-StorageManagement/Operational Microsoft-Windows-StorageSpaces-Driver/Diagnostic Microsoft-Windows-StorageSpaces-Driver/Operational Microsoft-Windows-StorageSpaces-ManagementAgent/WHC Microsoft-Windows-StorageSpaces-SpaceManager/Diagnostic Microsoft-Windows-StorageSpaces-SpaceManager/Operational Microsoft-Windows-Store/Operational Microsoft-Windows-SystemSettingsThreshold/Operational Microsoft-Windows-TaskScheduler/Maintenance Microsoft-Windows-TaskScheduler/Operational Microsoft-Windows-TCPIP/Operational Microsoft-Windows-TerminalServices-ClientUSBDevices/Admin Microsoft-Windows-TerminalServices-ClientUSBD