Problems receiving Windows event logs from nxlog
Posted: Thu Dec 24, 2015 7:28 am
Hi there,
I've got the following issue that the Windows host where NXLOG is configured, doesn't show up in the dashboard, nor in tcpdump.
I've examined the nxlog log file and show me these error messages:
2015-12-24 12:03:07 WARNING stopping nxlog service
2015-12-24 12:03:07 WARNING nxlog-ce received a termination request signal, exiting...
2015-12-24 12:03:12 ERROR Couldn't parse Exec block at C:\Program Files (x86)\nxlog\conf\nxlog.conf:58; couldn't parse statement at line 58, character 89 in C:\Program Files (x86)\nxlog\conf\nxlog.conf; procedure 'file_write()' does not exist or takes different arguments
2015-12-24 12:03:12 ERROR module 'out' has configuration errors, not adding to route '1' at C:\Program Files (x86)\nxlog\conf\nxlog.conf:62
2015-12-24 12:03:12 ERROR route 1 is not functional without output modules, ignored at C:\Program Files (x86)\nxlog\conf\nxlog.conf:62
2015-12-24 12:03:12 WARNING no routes defined!
2015-12-24 12:03:12 WARNING not starting unused module internal
2015-12-24 12:03:12 WARNING not starting unused module file1
2015-12-24 12:03:12 WARNING not starting unused module eventlog
2015-12-24 12:03:12 WARNING not starting unused module out
2015-12-24 12:03:12 INFO nxlog-ce-2.9.1347 started
Considering the nxlog configuration file, are spaces or line breaks allowed?
Best,
E
I've got the following issue that the Windows host where NXLOG is configured, doesn't show up in the dashboard, nor in tcpdump.
I've examined the nxlog log file and show me these error messages:
2015-12-24 12:03:07 WARNING stopping nxlog service
2015-12-24 12:03:07 WARNING nxlog-ce received a termination request signal, exiting...
2015-12-24 12:03:12 ERROR Couldn't parse Exec block at C:\Program Files (x86)\nxlog\conf\nxlog.conf:58; couldn't parse statement at line 58, character 89 in C:\Program Files (x86)\nxlog\conf\nxlog.conf; procedure 'file_write()' does not exist or takes different arguments
2015-12-24 12:03:12 ERROR module 'out' has configuration errors, not adding to route '1' at C:\Program Files (x86)\nxlog\conf\nxlog.conf:62
2015-12-24 12:03:12 ERROR route 1 is not functional without output modules, ignored at C:\Program Files (x86)\nxlog\conf\nxlog.conf:62
2015-12-24 12:03:12 WARNING no routes defined!
2015-12-24 12:03:12 WARNING not starting unused module internal
2015-12-24 12:03:12 WARNING not starting unused module file1
2015-12-24 12:03:12 WARNING not starting unused module eventlog
2015-12-24 12:03:12 WARNING not starting unused module out
2015-12-24 12:03:12 INFO nxlog-ce-2.9.1347 started
Considering the nxlog configuration file, are spaces or line breaks allowed?
Best,
E