nxlog client fails windows server 2016 max 256 sources
Posted: Fri Nov 30, 2018 12:44 pm
Hello all,
we have a windows 2016 server which was successfully sending log files to our nagios log server since we brought it online a few months ago. A couple days ago, we noticed that logs were no longer being sent. the nxlog client on the server starts/restarts successfully. however, in the nxlog client file, there is a error message:
"WARNING Due to a limitation in the Windows EventLog subsystem, a query cannot contain more than 256 sources."
and then a more extended message:
"WARNING The following sources are omitted to avoid exceeding the limit in the generated query: Microsoft-Windows-TerminalServices-PnPDevices/Admin Microsoft-Windows-TerminalServices-PnPDevices/Operational Microsoft-Windows-TerminalServices-Printers/Admin Microsoft-Windows-TerminalServices-Printers/Operational Microsoft-Windows-TerminalServices-RDPClient/Operational Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational Microsoft-Windows-TerminalServices-ServerUSBDevices/Admin Microsoft-Windows-TerminalServices-ServerUSBDevices/Operational Microsoft-Windows-TerminalServices-SessionBroker-Client/Admin Microsoft-Windows-TerminalServices-SessionBroker-Client/Operational Microsoft-Windows-TWinUI/Operational Microsoft-Windows-TZSync/Operational Microsoft-Windows-TZUtil/Operational Microsoft-Windows-UAC-FileVirtualization/Operational Microsoft-Windows-UAC/Operational Microsoft-Windows-UniversalTelemetryClient/Ope"
we need terminal services running on this system....
has anyone experienced this before?
thanks!
we have a windows 2016 server which was successfully sending log files to our nagios log server since we brought it online a few months ago. A couple days ago, we noticed that logs were no longer being sent. the nxlog client on the server starts/restarts successfully. however, in the nxlog client file, there is a error message:
"WARNING Due to a limitation in the Windows EventLog subsystem, a query cannot contain more than 256 sources."
and then a more extended message:
"WARNING The following sources are omitted to avoid exceeding the limit in the generated query: Microsoft-Windows-TerminalServices-PnPDevices/Admin Microsoft-Windows-TerminalServices-PnPDevices/Operational Microsoft-Windows-TerminalServices-Printers/Admin Microsoft-Windows-TerminalServices-Printers/Operational Microsoft-Windows-TerminalServices-RDPClient/Operational Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational Microsoft-Windows-TerminalServices-ServerUSBDevices/Admin Microsoft-Windows-TerminalServices-ServerUSBDevices/Operational Microsoft-Windows-TerminalServices-SessionBroker-Client/Admin Microsoft-Windows-TerminalServices-SessionBroker-Client/Operational Microsoft-Windows-TWinUI/Operational Microsoft-Windows-TZSync/Operational Microsoft-Windows-TZUtil/Operational Microsoft-Windows-UAC-FileVirtualization/Operational Microsoft-Windows-UAC/Operational Microsoft-Windows-UniversalTelemetryClient/Ope"
we need terminal services running on this system....
has anyone experienced this before?
thanks!